CVE-2026-90852 | luben zstd-jni up to 1.5.7-13 Dictionary Sharing ZstdCompressCtx.java ZstdCompressCtx.loadDict use after free (Issue 404)
A vulnerability labeled as critical has been found in luben zstd-jni up to 1.5.7-13. This vulnerability affects the function ZstdCompressCtx.loadDict of the file ZstdCompressCtx.java of the component Dictionary Sharing. Such manipulation leads to use after free.
This vulnerability is documented as CVE-2026-90852. The attack can be executed remotely. Additionally, an exploit exists.
The affected component should be upgraded.
The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.VulDB Recent EntriesRead More