High severity8.2NVD Advisory· Published Sep 12, 2026
CVE-2026-90560
CVE-2026-90560
Description
zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructor because offset and length arguments are never validated against the dictionary array bounds. Attackers can supply arbitrary offset or length values to read memory past the end of the supplied array, potentially causing JVM termination.
Affected products
2Patches
Vulnerability mechanics
References
6- github.com/luben/zstd-jni/blob/v1.2.0/src/main/java/com/github/luben/zstd/ZstdDictDecompress.javanvd
- github.com/luben/zstd-jni/blob/v1.5.7-13/src/main/java/com/github/luben/zstd/ZstdDictDecompress.javanvd
- github.com/luben/zstd-jni/commit/b74ab242d640c40897e62aab4c744ddfad1f915fnvd
- github.com/luben/zstd-jni/issues/405nvd
- github.com/luben/zstd-jni/releases/tag/v1.5.7-14nvd
- www.vulncheck.com/advisories/zstd-jni-1.2.0-through-1.5.7-13-out-of-bounds-read-via-zstddictdecompressnvd
News mentions
0No linked articles in our index yet.