CVE-2026-85228: Amazon Deep Java Library

Critical severity, CVSS 9.1. EPSS: 0.5% chance of exploitation in the next 30 days.

An integer overflow in the tensor buffer validation component in Amazon Deep Java Library (DJL) from 0.13.0 through 0.36.0 on all platforms might allow a remote unauthenticated actor to obtain information from adjacent process memory or cause a denial of service via a crafted tensor payload. To remediate this issue, users should upgrade to version 0.37.0 or above.

Affected products

  • Amazon Deep Java Library: from 0.13.0, up to and including 0.36.0

Published 2026-09-10. Last modified 2026-09-10.