{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3at-digest_projectt-digest3.3/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:t-digest_project:t-digest:3.1:*:*:*:*:*:*:*","cpe:2.3:a:t-digest_project:t-digest:3.2:*:*:*:*:*:*:*","cpe:2.3:a:t-digest_project:t-digest:3.3:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-87822"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["t-digest (3.1 - 3.3)"],"_cs_severities":["low"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eCVE-2026-87822 is a critical vulnerability within the t-digest library, specifically affecting the MergingDigest.fromBytes deserialization method in versions 3.1 through 3.3. The vulnerability stems from a failure to validate centroid mean values during the deserialization process. An attacker can supply a specially crafted serialized digest containing Not-a-Number (NaN) values. When the library attempts to merge these malformed digests, the presence of NaN values disrupts the standard sorting logic. This degradation shifts the computational complexity of the merge operation from O(n log n) to O(n squared). Defenders should note that this vulnerability primarily enables a denial-of-service (DoS) condition by inducing severe processing delays or exhaustion of CPU resources in applications that rely on untrusted input for digest deserialization.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in a denial-of-service condition due to computational complexity amplification. Organizations utilizing t-digest for high-throughput stream processing or large-scale data aggregation are at the highest risk, as the performance degradation could stall critical data pipelines and consume excessive compute resources, leading to potential service outages in systems that process serialized digest inputs from external or untrusted sources.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for engineering teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify all applications within the environment that import t-digest versions 3.1 through 3.3.\u003c/li\u003e\n\u003cli\u003eUpdate t-digest dependencies to a version where this validation logic has been addressed.\u003c/li\u003e\n\u003cli\u003eImplement input validation at the application boundary to inspect serialized data before passing it to the MergingDigest.fromBytes method.\u003c/li\u003e\n\u003cli\u003eMonitor for unusual CPU spikes in services handling serialized t-digest objects, which may indicate attempted exploitation.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-09T19:01:40Z","date_published":"2026-09-09T19:01:40Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-87822/","summary":"The MergingDigest.fromBytes method in t-digest versions 3.1 through 3.3 fails to validate centroid means during deserialization, allowing attackers to inject NaN values that trigger a denial-of-service via algorithmic complexity degradation.","title":"CVE-2026-87822: Deserialization Vulnerability in t-digest","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-87822/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:t-Digest_project:t-Digest:3.3:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}