{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/luben/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:luben:zstd-jni:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.2,"id":"CVE-2026-87795"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["zstd-jni (\u003c 1.5.7-14)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","memory-safety","java"],"_cs_type":"advisory","_cs_vendors":["luben"],"content_html":"\u003cp\u003eThe zstd-jni library, which provides Java bindings for the Zstandard compression algorithm, contains a memory safety vulnerability identified as CVE-2026-87795. The flaw exists within the ZstdDictCompress constructor, where the library fails to properly validate the offset and length parameters provided during dictionary creation.\u003c/p\u003e\n\u003cp\u003eBy supplying specially crafted offset or length values to the constructor, an attacker can trigger an out-of-bounds read within the native heap. This action potentially allows sensitive memory contents to be pulled into the compression dictionary. While the primary documented outcome is a JVM crash due to memory corruption, the underlying primitive provides a mechanism for information disclosure. The vulnerability affects all versions of zstd-jni prior to 1.5.7-14. This is particularly relevant for Java applications that process untrusted data using the ZstdDictCompress functionality, as the lack of parameter validation enables an attacker to manipulate memory access patterns directly.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation leads to memory corruption, which most commonly results in a denial-of-service condition via JVM crash. However, the out-of-bounds read capability poses a significant risk of information disclosure, where sensitive data residing in the native heap may be leaked into the application's compression dictionary. Applications that handle high-privilege or sensitive data and utilize zstd-jni for compression tasks are at the highest risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the update of all Java applications utilizing the zstd-jni library to version 1.5.7-14 or later to resolve the input validation issue in CVE-2026-87795.\u003c/p\u003e\n\u003cp\u003eAudit application codebases to identify if ZstdDictCompress is invoked with parameters derived from untrusted user input, as this represents the primary attack vector for this vulnerability.\u003c/p\u003e\n","date_modified":"2026-09-09T10:50:21Z","date_published":"2026-09-09T10:50:21Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-87795/","summary":"The zstd-jni library versions prior to 1.5.7-14 are vulnerable to an out-of-bounds memory read in the ZstdDictCompress constructor, allowing local or remote attackers to read native heap memory into a compression dictionary.","title":"Out-of-Bounds Memory Read in zstd-jni","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-87795/"}],"language":"en","title":"CraftedSignal Threat Feed - Luben","version":"https://jsonfeed.org/version/1.1"}