VYPR
High severity7.7NVD Advisory· Published Sep 9, 2026· Updated Sep 9, 2026

CVE-2026-87877

CVE-2026-87877

Description

zstd-jni versions before 1.5.7-14 fail to validate closed state in setDict, setLongMax, setLevel and setRefMultipleDDicts methods of stream classes. Attackers can call these methods on closed streams to write through freed native pointers, corrupting unrelated objects or crashing the JVM.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Luben/Zstd Jnireferences2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: <1.5.7-14

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.