{"id":"CVE-2026-90560","title":"zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructor because offset and length arguments are never validated against the dictionary array bounds","summary":"zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructor because offset and length arguments are never validated against the dictionary array bounds. Attackers can supply …","severity":"high","cvss":8.2,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","cwe":["CWE-125"],"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","affected":["exploit_intelligence","openshift_developer_tools_and_services","amq_clients","build_of_apache_camel_4_for_quarkus 3","build_of_apache_camel_for_spring_boot 4","build_of_apicurio_registry 3","build_of_debezium 3","build_of_quarkus","ceph_storage 9","enterprise_linux 8","enterprise_linux 9","fuse 7","jboss_enterprise_application_platform 8","jboss_enterprise_application_platform_expansion_pack","openshift_ai_rhoai"],"published":"2026-09-12","updated":"2026-09-14","sourceUpdated":"2026-09-14T16:17:27.797","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-90560","references":[{"url":"https://github.com/luben/zstd-jni","label":"disclosure@vulncheck.com"},{"url":"https://github.com/luben/zstd-jni/blob/v1.2.0/src/main/java/com/github/luben/zstd/ZstdDictDecompress.java#L37","label":"disclosure@vulncheck.com"},{"url":"https://github.com/luben/zstd-jni/blob/v1.5.7-13/src/main/java/com/github/luben/zstd/ZstdDictDecompress.java#L49","label":"disclosure@vulncheck.com"},{"url":"https://github.com/luben/zstd-jni/commit/b74ab242d640c40897e62aab4c744ddfad1f915f","label":"disclosure@vulncheck.com"},{"url":"https://github.com/luben/zstd-jni/issues/405","label":"disclosure@vulncheck.com"},{"url":"https://github.com/luben/zstd-jni/releases/tag/v1.5.7-14","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/zstd-jni-1.2.0-through-1.5.7-13-out-of-bounds-read-via-zstddictdecompress","label":"disclosure@vulncheck.com"},{"url":"https://github.com/luben/zstd-jni/issues/405","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-90560.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-90560"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532604"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-90560"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-90560"}],"tags":["nvd","csaf","vex","red-hat","cve.org","exploit-available"],"epss":0.00336,"epssPercentile":0.27097,"ingestedAt":"2026-09-14T15:23:07.478Z","exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-14T15:57:31.022495Z"},"slug":"CVE-2026-90560","body":"## Overview\n\nzstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructor because offset and length arguments are never validated against the dictionary array bounds. Attackers can supply arbitrary offset or length values to read memory past the end of the supplied array, potentially causing JVM termination.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Important · affected: Exploit Intelligence, OpenShift Developer Tools and Services, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Apache Camel for Spring Boot 4, Red Hat build of Apicurio Registry 3, Red Hat build of Debezium 3, … · no fix planned: Red Hat Ceph Storage 9, Exploit Intelligence, OpenShift Developer Tools and Services, Red Hat build of Apache Camel 4 for Quarkus 3, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-90560.json)","depth":"midnight","depthScore":57,"depthScoreParts":{"impact":45.1,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[{"seq":203119,"id":"CVE-2026-90560","ts":1789409575187,"field":"exploit_available","old":"false","new":"true"}]}