---
id: CVE-2026-90560
title: >-
  zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read
  vulnerability in the ZstdDictDecompress constructor because offset and length
  arguments are never validated against the dictionary array bounds
summary: >-
  zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read
  vulnerability in the ZstdDictDecompress constructor because offset and length
  arguments are never validated against the dictionary array bounds. Attackers
  can supply …
severity: high
cvss: 8.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H'
cwe:
  - CWE-125
vendor: Red Hat
product: Red Hat OpenShift AI (RHOAI)
affected:
  - exploit_intelligence
  - openshift_developer_tools_and_services
  - amq_clients
  - build_of_apache_camel_4_for_quarkus 3
  - build_of_apache_camel_for_spring_boot 4
  - build_of_apicurio_registry 3
  - build_of_debezium 3
  - build_of_quarkus
  - ceph_storage 9
  - enterprise_linux 8
  - enterprise_linux 9
  - fuse 7
  - jboss_enterprise_application_platform 8
  - jboss_enterprise_application_platform_expansion_pack
  - openshift_ai_rhoai
published: '2026-09-12'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T20:28:01.780'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90560'
references:
  - url: 'https://github.com/luben/zstd-jni'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/luben/zstd-jni/blob/v1.2.0/src/main/java/com/github/luben/zstd/ZstdDictDecompress.java#L37
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/luben/zstd-jni/blob/v1.5.7-13/src/main/java/com/github/luben/zstd/ZstdDictDecompress.java#L49
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/luben/zstd-jni/commit/b74ab242d640c40897e62aab4c744ddfad1f915f
    label: disclosure@vulncheck.com
  - url: 'https://github.com/luben/zstd-jni/issues/405'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/luben/zstd-jni/releases/tag/v1.5.7-14'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/zstd-jni-1.2.0-through-1.5.7-13-out-of-bounds-read-via-zstddictdecompress
    label: disclosure@vulncheck.com
  - url: 'https://github.com/luben/zstd-jni/issues/405'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-90560.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-90560'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2532604'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-90560'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90560'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71675'
tags:
  - nvd
  - csaf
  - vex
  - red-hat
  - cve.org
  - exploit-available
epss: 0.00619
epssPercentile: 0.47358
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-14T15:57:31.022495Z'
ingestedAt: '2026-09-14T15:23:07.478Z'
patched:
  - build_of_apache_camel_4_18_4_for_spring_boot 3.5.16
---

## Overview

zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructor because offset and length arguments are never validated against the dictionary array bounds. Attackers can supply arbitrary offset or length values to read memory past the end of the supplied array, potentially causing JVM termination.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · Important · affected: Exploit Intelligence, OpenShift Developer Tools and Services, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Apicurio Registry 3, Red Hat build of Debezium 3, Red Hat Ceph Storage 9, … · no fix planned: Red Hat Ceph Storage 9, Exploit Intelligence, OpenShift Developer Tools and Services, Red Hat build of Apache Camel 4 for Quarkus 3, … · updated 2026-09-24 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-90560.json)
- **RHSA-2026:71675** · Red Hat · fixed in: Red Hat build of Apache Camel 4.18.4 for Spring Boot 3.5.16 · released 2026-09-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:71675)
