CVE-2026-87795
zstd-jni versions before 1.5.7-14 fail to validate offset and length parameters in the ZstdDictCompress constructor, allowing out-of-bounds
CVSS
8.2
Alto
EPSS
—
KEV
—
Exploit Today
0
0-100
Publicado: 9 sept 2026 · Última mod.: 9 sept 2026 · CWE-125
Sin historial EPSS suficiente todavía.
zstd-jni versions before 1.5.7-14 fail to validate offset and length parameters in the ZstdDictCompress constructor, allowing out-of-bounds memory reads. Attackers can supply untrusted offset or length values to read native heap memory into the compression dictionary, typically causing JVM crashes.
- github.comhttps://github.com/luben/zstd-jni
- github.comhttps://github.com/luben/zstd-jni/blob/v1.5.7-13/src/main/java/com/github/luben/zstd/ZstdDictCompress.java
- github.comhttps://github.com/luben/zstd-jni/blob/v1.5.7-13/src/main/native/jni_fast_zstd.c
- github.comhttps://github.com/luben/zstd-jni/commit/0d64de4dee6606ff506be36c7f2e714ad0c80fdb
- github.comhttps://github.com/luben/zstd-jni/commit/1c4e5a6c3ce8458095225d987d669e6a0937734a
- github.comhttps://github.com/luben/zstd-jni/releases/tag/v1.5.7-14
- github.comhttps://github.com/luben/zstd-jni/security/advisories/GHSA-ff36-7w3w-g8rm
- www.vulncheck.comhttps://www.vulncheck.com/advisories/zstd-jni-1.2.0-through-1.5.7-13-out-of-bounds-read-via-zstddictcompress
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-877364.3 MED—
——0An issue was discovered in the mirage-crypto-ec package before 2.3.0 for OCaml. There is an EC public key out-of-bounds read for compressed points.9hCVE-2026-816465.9 MED—
——0Out-of-bounds read vulnerability in the graphics module.
Impact: Successful exploitation of this vulnerability may affect availability.10hCVE-2026-493147.3 ALT—
——0OOB write vulnerability in the rendering and composition module.
Impact: Successful exploitation of this vulnerability may affect availability.10hCVE-2026-87650——
——0Out of bounds read in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)13hCVE-2026-87640——
——0Out of bounds read in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)13hCVE-2026-87604——
——0Out of bounds read in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)13h