Beveiligingsadvies

CVE-2026-87795

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-09-09 10:07:28
Laatst bijgewerkt 2026-09-14 13:02:51
Toegewezen door VulnCheck
CVSS-score 8.8
Status PUBLISHED

Beschrijving

zstd-jni versions before 1.5.7-14 fail to validate offset and length parameters in the ZstdDictCompress constructor, allowing out-of-bounds memory reads. Attackers can supply untrusted offset or length values to read native heap memory into the compression dictionary, typically causing JVM crashes.