CVE-2026-89046 | luben zstd-jni up to 1.5.7-13 native frame-header parser Zstd.getFrameContentSize srcPosition out-of-bounds

SecurityVulns

A vulnerability was found in luben zstd-jni up to 1.5.7-13 and classified as critical. This affects the function Zstd.getFrameContentSize of the component native frame-header parser. The manipulation of the argument srcPosition results in out-of-bounds read.

This vulnerability was named CVE-2026-89046. The attack may be performed from remote. There is no available exploit.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More