VYPR
High severity8.2NVD Advisory· Published Sep 9, 2026

CVE-2026-87795

CVE-2026-87795

Description

zstd-jni versions before 1.5.7-14 fail to validate offset and length parameters in the ZstdDictCompress constructor, allowing out-of-bounds memory reads. Attackers can supply untrusted offset or length values to read native heap memory into the compression dictionary, typically causing JVM crashes.

Affected products

2
  • Luben/Zstd Jnillm-fuzzy2 versions
    <1.5.7-14+ 1 more
    • (no CPE)range: <1.5.7-14
    • (no CPE)

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.