Out-of-Bounds Memory Read in zstd-jni by Luben Technologies
CVE-2026-87795

8.8HIGH

Key Information:

Vendor

Luben

Status
Vendor
CVE Published:
9 September 2026

What is CVE-2026-87795?

The zstd-jni library, prior to version 1.5.7-14, contains a vulnerability that arises from improper validation of offset and length parameters in the ZstdDictCompress constructor. This flaw allows attackers to manipulate these parameters, potentially leading to out-of-bounds memory reads. When exploited, it can read arbitrary data from the native heap memory, resulting in unintentional information leakage and causing stability issues such as JVM crashes. Users of affected versions are advised to upgrade to the latest version to mitigate this vulnerability.

Affected Version(s)

zstd-jni 1.2.0 < 1.5.7-14

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
Low
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yu Bao, PayPal Cyber Security Team
.