luben zstd-jni
9 known vulnerabilities in luben zstd-jni, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-90852 CVSS 5.5 medium A vulnerability has been found in luben zstd-jni up to 1.5.7-13. This vulnerability affects the function ZstdCompressCtx.loadDict of the…
- CVE-2026-90560 CVSS 8.8 high zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructor because offset…
- CVE-2026-89046 CVSS 8.8 high zstd-jni versions 1.5.5-6 through 1.5.7-13 contain an out-of-bounds read vulnerability in Zstd.getFrameContentSize that fails to validate…
- CVE-2026-89045 CVSS 5.1 medium zstd-jni versions 1.4.8-4 through 1.5.7-13 fail to validate negative length parameters in ZstdInputStreamNoFinalizer.read(), allowing…
- CVE-2026-87877 CVSS 7.0 high zstd-jni versions before 1.5.7-14 fail to validate closed state in setDict, setLongMax, setLevel and setRefMultipleDDicts methods of…
- CVE-2026-87825 CVSS 7.0 high zstd-jni before 1.5.7-14 contains a use-after-free vulnerability where streams and contexts hold a dictionary's shared lock only during…
- CVE-2026-87824 CVSS 8.7 high zstd-jni before 1.5.7-14 fails to validate the samples buffer capacity in Zstd.trainFromBufferDirect, allowing attackers to read past…
- CVE-2026-87823 CVSS 8.8 high zstd-jni before 1.5.7-14 performs 32-bit signed bounds checks on three direct-ByteBuffer frame-size native methods, allowing out-of-bounds…
- CVE-2026-87795 CVSS 8.8 high zstd-jni versions before 1.5.7-14 fail to validate offset and length parameters in the ZstdDictCompress constructor, allowing…