CVE-2026-90560 | luben zstd-jni up to 1.5.7-13 Dictionary Decompression ZstdDictDecompress constructor offset/length out-of-bounds

SecurityVulns

A vulnerability, which was classified as critical, has been found in luben zstd-jni up to 1.5.7-13. Affected by this issue is the function ZstdDictDecompress constructor of the component Dictionary Decompression. Performing a manipulation of the argument offset/length results in out-of-bounds read.

This vulnerability was named CVE-2026-90560. The attack may be initiated remotely. There is no available exploit.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More