CVE-2026-87824: Luben Zstd-Jni
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
zstd-jni before 1.5.7-14 fails to validate the samples buffer capacity in Zstd.trainFromBufferDirect, allowing attackers to read past buffer boundaries by supplying oversized per-sample lengths. Attackers can trigger out-of-bounds memory access by providing crafted sample length arrays that cause the native implementation to walk past the buffer allocation, resulting in JVM termination.
Affected products
- Luben Zstd-Jni: from 1.3.3-1, before 1.5.7-14 (fixed in 1.5.7-14)
Published 2026-09-09. Last modified 2026-09-20.