GHSA-vc57-7frc-7vqxHighCVSS 8.2

zstd-jni versions before 1.5.7-14 fail to validate offset and length parameters in the...

Published
September 9, 2026
Last Modified
September 9, 2026

🔗 CVE IDs covered (1)

📋 Description

zstd-jni versions before 1.5.7-14 fail to validate offset and length parameters in the ZstdDictCompress constructor, allowing out-of-bounds memory reads. Attackers can supply untrusted offset or length values to read native heap memory into the compression dictionary, typically causing JVM crashes.

🔗 References (10)