{"id":"CVE-2026-90560","description":"zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructor because offset and length arguments are never validated against the dictionary array bounds. Attackers can supply arbitrary offset or length values to read memory past the end of the supplied array, potentially causing JVM termination.","cvssScore":8.8,"cvssVersion":"4.0","cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","cvssMetrics":[{"version":"4.0","score":8.8,"severity":"HIGH","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","source":"disclosure@vulncheck.com","type":"Secondary"},{"version":"3.1","score":8.2,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","source":"disclosure@vulncheck.com","type":"Primary"}],"cwes":["CWE-125"],"resolved":"NO-EXPLOIT-PUBLISHED","published":"2026-09-12","lastModified":"2026-09-12","references":[{"url":"https://github.com/luben/zstd-jni/commit/b74ab242d640c40897e62aab4c744ddfad1f915f","source":"patch-hint","tags":["commit"]},{"url":"https://github.com/luben/zstd-jni","source":"disclosure@vulncheck.com"},{"url":"https://github.com/luben/zstd-jni/blob/v1.2.0/src/main/java/com/github/luben/zstd/ZstdDictDecompress.java#L37","source":"disclosure@vulncheck.com"},{"url":"https://github.com/luben/zstd-jni/blob/v1.5.7-13/src/main/java/com/github/luben/zstd/ZstdDictDecompress.java#L49","source":"disclosure@vulncheck.com"},{"url":"https://github.com/luben/zstd-jni/issues/405","source":"disclosure@vulncheck.com"},{"url":"https://github.com/luben/zstd-jni/releases/tag/v1.5.7-14","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/zstd-jni-1.2.0-through-1.5.7-13-out-of-bounds-read-via-zstddictdecompress","source":"disclosure@vulncheck.com"}],"reasoning":{"decidingSource":"no-exploit-published","decidingReason":"This CVE is not listed in CISA KEV, CISA Vulnrichment records no active exploitation, and no reviewed exploit catalogue carries an entry for it. Nobody has published something a stranger can run, so it is not a candidate for a rule ahead of the ones where somebody has; an upstream fix path does exist, so the remediation half of the candidacy still holds. This is a statement about what has been published, not about whether the defect is reachable or serious.","verdicts":[{"rule":"rejected","stage":"identity","outcome":"no-match"},{"rule":"armr-patch-file","stage":"scope","outcome":"no-match"},{"rule":"armr-secure-rule-file","stage":"scope","outcome":"no-match"},{"rule":"manual-classification","stage":"scope","outcome":"no-match"},{"rule":"h2-history","stage":"scope","outcome":"no-match"},{"rule":"non-java-upstream","stage":"scope","outcome":"no-match"},{"rule":"oracle-component","stage":"scope","outcome":"no-match"},{"rule":"osv-maven","stage":"scope","outcome":"no-match"},{"rule":"cna-maven-package","stage":"scope","outcome":"matched","status":"QUEUED-FOR-REVIEW","detail":"CNA declares the affected component is a Maven artifact"},{"rule":"patch-hint","stage":"disposition","outcome":"matched","status":"MITIGATION-CANDIDATE","detail":"References include candidate fix URL (commit tier): https://github.com/luben/zstd-jni/commit/b74ab242d640c40897e62aab4c744ddfad1f915f"},{"rule":"open-source-maven","stage":"disposition","outcome":"skipped"},{"rule":"poc-derivable","stage":"disposition","outcome":"skipped"},{"rule":"no-exploit","stage":"disposition","outcome":"skipped"},{"rule":"secure-rule-match","stage":"disposition","outcome":"no-match"},{"rule":"below-action-threshold","stage":"disposition","outcome":"no-match","detail":"Severity is HIGH — only MEDIUM/LOW are deprioritized"},{"rule":"no-exploit-published","stage":"disposition","outcome":"matched","status":"NO-EXPLOIT-PUBLISHED","detail":"No working exploit has been published, and an upstream fix path does exist, so the remediation half of the candidacy still holds.","decisive":true}],"patchHintUrl":"https://github.com/luben/zstd-jni/commit/b74ab242d640c40897e62aab4c744ddfad1f915f","patchHintTier":"commit"},"assessment":{"record":{"state":"active"},"protection":{"level":"none"},"action":{"state":"unverified","type":"patch-rule"},"review":{"state":"automated","basis":"upstream-data"}},"signals":{"hasPOC":false,"pocCount":0},"kev":{"inKEV":false},"epss":{"available":true,"score":0.00336,"percentile":0.2667},"ssvc":{"available":true,"exploitation":"poc","automatable":"yes","technicalImpact":"partial"},"patchHintUrl":"https://github.com/luben/zstd-jni/commit/b74ab242d640c40897e62aab4c744ddfad1f915f","patchHintTier":"commit"}