CVE-2026-87795: Luben Zstd-Jni

High severity, CVSS 8.2. EPSS: 0.6% chance of exploitation in the next 30 days.

zstd-jni versions before 1.5.7-14 fail to validate offset and length parameters in the ZstdDictCompress constructor, allowing out-of-bounds memory reads. Attackers can supply untrusted offset or length values to read native heap memory into the compression dictionary, typically causing JVM crashes.

Affected products

  • Luben Zstd-Jni: from 1.2.0, before 1.5.7-14 (fixed in 1.5.7-14)

Published 2026-09-09. Last modified 2026-09-14.