Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vc57-7frc-7vqx

Опубликовано: 09 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.8
CVSS3: 8.2

Описание

zstd-jni versions before 1.5.7-14 fail to validate offset and length parameters in the ZstdDictCompress constructor, allowing out-of-bounds memory reads. Attackers can supply untrusted offset or length values to read native heap memory into the compression dictionary, typically causing JVM crashes.

zstd-jni versions before 1.5.7-14 fail to validate offset and length parameters in the ZstdDictCompress constructor, allowing out-of-bounds memory reads. Attackers can supply untrusted offset or length values to read native heap memory into the compression dictionary, typically causing JVM crashes.

EPSS

Процентиль: 28%
0.00344
Низкий

8.8 High

CVSS4

8.2 High

CVSS3

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 8.2
ubuntu
6 дней назад

(zstd-jni versions before 1.5.7-14 fail to validate offset and length p ...)

CVSS3: 8.2
redhat
7 дней назад

zstd-jni versions before 1.5.7-14 fail to validate offset and length parameters in the ZstdDictCompress constructor, allowing out-of-bounds memory reads. Attackers can supply untrusted offset or length values to read native heap memory into the compression dictionary, typically causing JVM crashes.

CVSS3: 8.2
nvd
7 дней назад

zstd-jni versions before 1.5.7-14 fail to validate offset and length parameters in the ZstdDictCompress constructor, allowing out-of-bounds memory reads. Attackers can supply untrusted offset or length values to read native heap memory into the compression dictionary, typically causing JVM crashes.

CVSS3: 8.2
debian
7 дней назад

zstd-jni versions before 1.5.7-14 fail to validate offset and length p ...

CVSS3: 8.2
fstec
около 1 месяца назад

Уязвимость компонента ZstdDictCompress библиотеки сжатия данных zstd-jni, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 28%
0.00344
Низкий

8.8 High

CVSS4

8.2 High

CVSS3

Дефекты

CWE-125