VulnSea

luben has 6 CVEs on record. Disclosure cadence is accelerating: 6 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 6. The median CVSS is 7.6 (high). None have a confirmed exploitation report. The most common weakness class is CWE-416 (3).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.6
Publish → KEV
Last 90 days
6 prev 0

Products

  • zstd-jni 6
6
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

luben vulnerabilities

CVEs affecting luben, newest first. Open any entry for full detail, references, and exploit status.

6 CVEsRSS

CVE-2026-90852High· 7.3PoC
6d ago

A vulnerability has been found in luben zstd-jni up to 1.5.7-13

A vulnerability has been found in luben zstd-jni up to 1.5.7-13. This vulnerability affects the function ZstdCompressCtx.loadDict of the file ZstdCompressCtx.java of the component Dictionary Sharing. Such manipulation leads to use after …

Midnightluben · zstd-jniEPSS 0.31%via NVD
CVE-2026-89045Medium· 4.0PoC
1w ago

zstd-jni versions 1.4.8-4 through 1.5.7-13 fail to validate negative length parameters in ZstdInputStreamNoFinalizer.read(), allowing attackers to trigger infinite loops

zstd-jni versions 1.4.8-4 through 1.5.7-13 fail to validate negative length parameters in ZstdInputStreamNoFinalizer.read(), allowing attackers to trigger infinite loops. Attackers can pass negative length values to cause the read method…

Twilightluben · zstd-jniEPSS 0.12%via NVD
CVE-2026-87825High· 7.7PoC
1w ago

zstd-jni before 1.5.7-14 contains a use-after-free vulnerability where streams and contexts hold a dictionary's shared lock only during the load call, allowing the dictionary to be closed while still referenced

zstd-jni before 1.5.7-14 contains a use-after-free vulnerability where streams and contexts hold a dictionary's shared lock only during the load call, allowing the dictionary to be closed while still referenced. Attackers can close a dic…

Midnightluben · zstd-jniEPSS 0.13%via NVD
CVE-2026-87877High· 7.7PoC
1w ago

zstd-jni versions before 1.5.7-14 fail to validate closed state in setDict, setLongMax, setLevel and setRefMultipleDDicts methods of stream classes

zstd-jni versions before 1.5.7-14 fail to validate closed state in setDict, setLongMax, setLevel and setRefMultipleDDicts methods of stream classes. Attackers can call these methods on closed streams to write through freed native pointer…

Midnightluben · zstd-jniEPSS 0.20%via NVD
CVE-2026-87823High· 8.2PoC
1w ago

zstd-jni before 1.5.7-14 performs 32-bit signed bounds checks on three direct-ByteBuffer frame-size native methods, allowing out-of-bounds memory reads via negative or overflowing offsets

zstd-jni before 1.5.7-14 performs 32-bit signed bounds checks on three direct-ByteBuffer frame-size native methods, allowing out-of-bounds memory reads via negative or overflowing offsets. Attackers can supply negative offset values near…

Midnightluben · zstd-jniEPSS 0.43%via NVD
CVE-2026-87824High· 7.5
1w ago

zstd-jni before 1.5.7-14 fails to validate the samples buffer capacity in Zstd.trainFromBufferDirect, allowing attackers to read past buffer boundaries by supplying oversized per-sample lengths

zstd-jni before 1.5.7-14 fails to validate the samples buffer capacity in Zstd.trainFromBufferDirect, allowing attackers to read past buffer boundaries by supplying oversized per-sample lengths. Attackers can trigger out-of-bounds memory…

Twilightluben · zstd-jniEPSS 0.39%via NVD
luben vulnerabilities (CVEs) · VulnSea