Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-87795

HIGH NVD
CVSS Score 8.2
Severity HIGH
Published Sep 09, 2026
Vendor unknown

Description

zstd-jni versions before 1.5.7-14 fail to validate offset and length parameters in the ZstdDictCompress constructor, allowing out-of-bounds memory reads. Attackers can supply untrusted offset or length values to read native heap memory into the compression dictionary, typically causing JVM crashes.

References