zstd-jni versions 1.4.8-4 through 1.5.7-13 fail to validate negative length parameters in ZstdInputStreamNoFinalizer.read(), allowing attackers to trigger infinite loops. Attackers can pass negative length values to cause the read method to spin indefinitely while holding the stream monitor, blocking all other threads from accessing the stream.
History

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 11 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
First Time appeared Luben
Luben zstd-jni
Vendors & Products Luben
Luben zstd-jni

Thu, 10 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description zstd-jni versions 1.4.8-4 through 1.5.7-13 fail to validate negative length parameters in ZstdInputStreamNoFinalizer.read(), allowing attackers to trigger infinite loops. Attackers can pass negative length values to cause the read method to spin indefinitely while holding the stream monitor, blocking all other threads from accessing the stream.
Title zstd-jni 1.4.8-4 through 1.5.7-13 Denial of Service via Negative Length
Weaknesses CWE-835
References
Metrics cvssV3_1

{'score': 4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2026-09-10T17:39:34.866Z

Updated: 2026-09-10T17:39:34.866Z

Reserved: 2026-09-10T16:45:18.503Z

Link: CVE-2026-89045

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-10T18:18:16.410

Modified: 2026-09-10T19:54:25.810

Link: CVE-2026-89045

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-10T17:39:34Z

Links: CVE-2026-89045 - Bugzilla