🚨 CVE-2026-87795
zstd-jni versions before 1.5.7-14 fail to validate offset and length parameters in the ZstdDictCompress constructor, allowing out-of-bounds memory reads. Attackers can supply untrusted offset or length values to read native heap memory into the compression dictionary, typically causing JVM crashes.
🎖@cveNotify

GitHub
GitHub - luben/zstd-jni: JNI binding for Zstd
JNI binding for Zstd. Contribute to luben/zstd-jni development by creating an account on GitHub.
September 9, 2026 39