Integer Overflow Vulnerability in Amazon Deep Java Library
CVE-2026-85228

8.8HIGH

Key Information:

Vendor

Amazon

Vendor
CVE Published:
10 September 2026

What is CVE-2026-85228?

An integer overflow vulnerability has been identified in the tensor buffer validation component of Amazon Deep Java Library, affecting versions from 0.13.0 up to 0.36.0 across all platforms. This flaw may allow a remote actor to gain unauthorized access to information from adjacent process memory or potentially trigger a denial of service by utilizing a specially crafted tensor payload. Users are strongly advised to upgrade to version 0.37.0 or higher to mitigate this risk.

Affected Version(s)

Deep Java Library 0.13.0 <= 0.36.0

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.