Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-87962

HIGH NVD
CVSS Score 7.5
Severity HIGH
Published Sep 10, 2026
Vendor unknown

Description

t-digest versions 3.1 through 3.3 contain a denial of service vulnerability in MergingDigest.fromBytes that fails to validate length and capacity fields from serialized data. Attackers can supply crafted serialized digests with mismatched header fields to trigger ArrayIndexOutOfBoundsException or NegativeArraySizeException, aborting the parsing thread.

References