---
id: CVE-2026-85228
title: Integer overflow in tensor buffer validation in Deep Java Library
summary: >-
  An integer overflow in the tensor buffer validation component in Amazon Deep
  Java Library (DJL) from 0.13.0 through 0.36.0 on all platforms might allow a
  remote unauthenticated actor to obtain information from adjacent process
  memory or …
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'
cvssSource: cna
cwe:
  - CWE-190
vendor: Amazon
product: Deep Java Library
affected:
  - deep_java_library >= 0.13.0 <= 0.36.0
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-10T18:20:24.588165Z'
published: '2026-09-10'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T18:20:34.948Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-85228'
references:
  - url: 'https://github.com/deepjavalibrary/djl/releases/tag/v0.37.0'
  - url: 'https://aws.amazon.com/security/security-bulletins/2026-106-aws/'
tags:
  - cve.org
epss: 0.00539
epssPercentile: 0.42863
ingestedAt: '2026-09-11T16:45:48.028Z'
---

## Overview

An integer overflow in the tensor buffer validation component in Amazon Deep Java Library (DJL) from 0.13.0 through 0.36.0 on all platforms might allow a remote unauthenticated actor to obtain information from adjacent process memory or cause a denial of service via a crafted tensor payload.



To remediate this issue, users should upgrade to version 0.37.0 or above.

## Affected

- `deep_java_library >= 0.13.0 <= 0.36.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
