CVE-2026-85228
An integer overflow in the tensor buffer validation component in Amazon Deep Java Library (DJL) from 0.13.0 through 0.36.0 on all platforms might allow a remote unauthenticated actor to obtain information from adjacent process memory or cause a denial of service via a crafted tensor payload. To remediate this issue, users should upgrade to version 0.37.0 or above.
- Published Sep 10, 2026
- CVSS 8.8 high
- 0.5% chance of exploitation in the next 30 days (EPSS)
- A fix is available
Affected software
In the news
- CVE-2026-85228 - Integer overflow in tensor buffer validation in Deep Java Library AWS Security Bulletins ·