HIGH
CVE-2026-90560
CVSS
8.2
Description
zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructor because offset and length arguments are never validated against the dictionary array bounds. Attackers can supply arbitrary offset or length values to read memory past the end of the supplied array, potentially causing JVM termination.
Weakness (CWE)
CWE-125
Out-of-bounds Read
EPSS Score
0.34%
Probability of exploitation in next 30 days
27.1th percentile
References
https://github.com/luben/zstd-jni
https://github.com/luben/zstd-jni/blob/v1.2.0/src/main/java/com/github/luben/zstd/ZstdDictDecompress.java#L37
https://github.com/luben/zstd-jni/blob/v1.5.7-13/src/main/java/com/github/luben/zstd/ZstdDictDecompress.java#L49
https://github.com/luben/zstd-jni/commit/b74ab242d640c40897e62aab4c744ddfad1f915f
https://github.com/luben/zstd-jni/issues/405
https://github.com/luben/zstd-jni/releases/tag/v1.5.7-14
https://www.vulncheck.com/advisories/zstd-jni-1.2.0-through-1.5.7-13-out-of-bounds-read-via-zstddictdecompress
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.