VYPR
High severity8.2NVD Advisory· Published Sep 10, 2026· Updated Sep 10, 2026

CVE-2026-89046

CVE-2026-89046

Description

zstd-jni versions 1.5.5-6 through 1.5.7-13 contain an out-of-bounds read vulnerability in Zstd.getFrameContentSize that fails to validate negative srcPosition arguments. Attackers can supply negative offset values that bypass bounds checks and reach the native frame-header parser, causing out-of-bounds memory reads that lead to information disclosure or JVM crashes.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Luben/Zstd Jnillm-fuzzy2 versions
    1.5.5-6 - 1.5.7-13+ 1 more
    • (no CPE)range: 1.5.5-6 - 1.5.7-13
    • (no CPE)

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.