CVE-2026-89046High· 8.2▾ MidnightPoC availableA flaw was found in zstd-jni. This out-of-bounds read vulnerability in the Zstd.getFrameContentSize function occurs because it fails to validate negative srcPosition arguments. A remote attacker can supply negative offset values, bypassing…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 45.1 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the vendor's CSAF advisory record, not NVD.
Exploit-prediction probability, daily snapshots since Sep 11.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.6%
Last analysed / modified upstream
A flaw was found in zstd-jni. This out-of-bounds read vulnerability in the Zstd.getFrameContentSize function occurs because it fails to validate negative srcPosition arguments. A remote attacker can supply negative offset values, bypassing bounds checks and accessing the native frame-header parser. This can lead to out-of-bounds memory reads, resulting in information disclosure or a Java Virtual Machine (JVM) crash.
zstd-jni: zstd-jni: Information disclosure or denial of service via out-of-bounds read — rated Important by Red Hat. Released 2026-09-10, updated 2026-09-21.
Affected:
No fix planned:
Not affected:
Fix deferred
Workarounds / mitigations:
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-87795High· 8.2com.github.luben/zstd-jni: zstd-jni: Out-of-bounds read in ZstdDictCompress constructor leads to denial of service (CVE-2026-87795)
CVE-2026-90815Medium· 6.3A vulnerability has been found in FFmpeg up to 4.4.6/5.1.8/6.1.4/7.1.3/8.0.1
CVE-2026-90698Medium· 5.3A security flaw has been discovered in memcached 1.6.41/1.6.42/1.6.43
CVE-2026-92925High· 7.1A flaw was found in Redis community
CVE-2026-85234High· 7.5A flaw was found in tftp-hpa
CVE-2026-91786Medium· 6.1A flaw was found in GNOME Shell