CVE-2026-87795High· 8.2▾ MidnightPoC availableA flaw was found in zstd-jni. This vulnerability occurs due to insufficient validation of offset and length parameters within the `ZstdDictCompress` constructor. An attacker can exploit this by providing untrusted values, leading to an out…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 45.1 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the vendor's CSAF advisory record, not NVD.
Exploit-prediction probability, daily snapshots since Sep 11.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.3%
Last analysed / modified upstream
A flaw was found in zstd-jni. This vulnerability occurs due to insufficient validation of offset and length parameters within the ZstdDictCompress constructor. An attacker can exploit this by providing untrusted values, leading to an out-of-bounds memory read. This can result in the disclosure of sensitive native heap memory and cause the Java Virtual Machine (JVM) to crash, leading to a denial of service.
com.github.luben/zstd-jni: zstd-jni: Out-of-bounds read in ZstdDictCompress constructor leads to denial of service — rated Important by Red Hat. Released 2026-09-09, updated 2026-09-21.
Affected:
No fix planned:
Not affected:
Fix deferred
Workarounds / mitigations:
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-89046High· 8.2zstd-jni: zstd-jni: Information disclosure or denial of service via out-of-bounds read (CVE-2026-89046)
CVE-2026-92925High· 7.1A flaw was found in Redis community
CVE-2026-85234High· 7.5A flaw was found in tftp-hpa
CVE-2026-91786Medium· 6.1A flaw was found in GNOME Shell
CVE-2026-90994Medium· 4.0A flaw was found in sssd, specifically within the PAM (Pluggable Authentication Modules) responder's protocol v1 parser, pam_parse_in_data()
CVE-2025-49796Critical· 9.1A vulnerability was found in libxml2