CVE-2026-87823: Integer Overflow or Wraparound in luben zstd-jni
CVE-2026-87823 is a high-severity integer overflow or wraparound vulnerability in the zstd-jni library before version 1.5.7-14. It involves improper 32-bit signed bounds checks on certain native methods handling direct-ByteBuffer frame sizes, which can be exploited by supplying negative or overflowing offset values. This can lead to out-of-bounds memory reads, potentially causing JVM termination or unauthorized data disclosure from unintended memory locations.
AI Analysis
Technical Summary
The vulnerability in zstd-jni prior to 1.5.7-14 arises from performing 32-bit signed bounds checks on three native methods that handle direct-ByteBuffer frame sizes. Attackers can exploit this by providing negative offset values near Integer.MIN_VALUE, resulting in out-of-bounds memory reads. This can cause the Java Virtual Machine to crash or allow extraction of arbitrary frame size data from memory areas not intended to be accessed by the application.
Potential Impact
Successful exploitation can cause the JVM to terminate unexpectedly or allow attackers to read arbitrary memory contents, potentially leading to information disclosure. The vulnerability does not require privileges or user interaction and has a low complexity of attack, making it a significant risk in affected environments.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, avoid using affected versions of zstd-jni in untrusted environments or apply additional memory access controls as a precaution.
CVE-2026-87823: Integer Overflow or Wraparound in luben zstd-jni
Description
CVE-2026-87823 is a high-severity integer overflow or wraparound vulnerability in the zstd-jni library before version 1.5.7-14. It involves improper 32-bit signed bounds checks on certain native methods handling direct-ByteBuffer frame sizes, which can be exploited by supplying negative or overflowing offset values. This can lead to out-of-bounds memory reads, potentially causing JVM termination or unauthorized data disclosure from unintended memory locations.
CVSS v4.0
Score 8.8high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in zstd-jni prior to 1.5.7-14 arises from performing 32-bit signed bounds checks on three native methods that handle direct-ByteBuffer frame sizes. Attackers can exploit this by providing negative offset values near Integer.MIN_VALUE, resulting in out-of-bounds memory reads. This can cause the Java Virtual Machine to crash or allow extraction of arbitrary frame size data from memory areas not intended to be accessed by the application.
Potential Impact
Successful exploitation can cause the JVM to terminate unexpectedly or allow attackers to read arbitrary memory contents, potentially leading to information disclosure. The vulnerability does not require privileges or user interaction and has a low complexity of attack, making it a significant risk in affected environments.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, avoid using affected versions of zstd-jni in untrusted environments or apply additional memory access controls as a precaution.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-09T10:32:34.110Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6aa172cbacd9273b49784b78
Added to database: 09/09/2026, 14:52:59 UTC
Last enriched: 09/09/2026, 15:07:22 UTC
Last updated: 09/09/2026, 15:07:58 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.