CVE-2026-87877

zstd-jni versions before 1.5.7-14 fail to validate closed state in setDict, setLongMax, setLevel and setRefMultipleDDicts methods of stream classes. Attackers can call these methods on closed streams to write through freed native pointers, corrupting unrelated objects or crashing the JVM.

Scoring

Severity
HIGH
CVSS base score
7.7
CVSS vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
CWE
CWE-416
Published
2026-09-09
Last modified
2026-09-09

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs