GHSA-5mvm-7cx8-x4wfHighCVSS 9.1

An integer overflow in the tensor buffer validation component in Amazon Deep Java Library (DJL)...

Published
September 10, 2026
Last Modified
September 10, 2026

🔗 CVE IDs covered (1)

📋 Description

An integer overflow in the tensor buffer validation component in Amazon Deep Java Library (DJL) from 0.13.0 through 0.36.0 on all platforms might allow a remote unauthenticated actor to obtain information from adjacent process memory or cause a denial of service via a crafted tensor payload.

To remediate this issue, users should upgrade to version 0.37.0 or above.

🔗 References (4)