HIGH

CVE-2026-90560

2026-09-12 CVSS v3.1
CVSS
8.2

Description

zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructor because offset and length arguments are never validated against the dictionary array bounds. Attackers can supply arbitrary offset or length values to read memory past the end of the supplied array, potentially causing JVM termination.

Weakness (CWE)

CWE-125 Out-of-bounds Read

EPSS Score

0.34%
Probability of exploitation in next 30 days
27.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE