Junglewise Threat Intelligence

CVE-2026-87877: zstd-jni use-after-free in stream setter methods

CVE-2026-87877 · Severity: high · CVSS 7.7 · Published 2026-09-09

Technologies: Luben Zstd-Jni. Vendors: Luben.

Executive brief

zstd-jni is a Java library providing compression and decompression via JNI bindings to the Zstandard algorithm. Versions before 1.5.7-14 fail to validate whether stream objects have been closed before allowing setter methods to execute, allowing attackers to write through freed native memory pointers and corrupt other objects or crash the Java virtual machine.

Technical details

The vulnerability is a use-after-free in stream classes resulting from missing closed-state validation. The affected methods—setDict, setLongMax, setLevel, and setRefMultipleDDicts—fail to check whether their parent stream object has been closed before dereferencing native pointers. An attacker with local JVM access can invoke these methods on a closed stream instance, causing writes through dangling pointers to freed native memory, leading to heap corruption, information disclosure, or denial of service (JVM crash). The vulnerability is fixed in zstd-jni 1.5.7-14 and later.

Affected products

  • Luben zstd-jni before 1.5.7-14

Timeline

  • 2026-09-09: disclosed
  • 2026-08-16: patched: Fixed in version 1.5.7-14

References

Related threats