CVE-2026-87795 UNKNOWN

CVE-2026-87795

Published: 2026-09-09

Description

zstd-jni versions before 1.5.7-14 fail to validate offset and length parameters in the ZstdDictCompress constructor, allowing out-of-bounds memory reads. Attackers can supply untrusted offset or length values to read native heap memory into the compression dictionary, typically causing JVM crashes.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…