Junglewise Threat Intelligence

CVE-2026-89045: zstd-jni input validation bypass in ZstdInputStreamNoFinalizer.read()

CVE-2026-89045 · Severity: medium · CVSS 4 · Published 2026-09-10

Technologies: Luben Zstd-Jni. Vendors: Luben.

Executive brief

zstd-jni is a Java library that provides compression/decompression functionality using the Zstandard algorithm. A flaw in the ZstdInputStreamNoFinalizer.read() method fails to validate negative length parameters, allowing an attacker to trigger infinite loops that freeze the stream and block all other threads from using it, causing a denial of service.

Technical details

The vulnerability is an input validation flaw in the ZstdInputStreamNoFinalizer.read() method, which does not properly check for negative length parameters. When a negative length value is passed to the read() method, it enters an infinite loop while holding the stream's monitor lock, preventing other threads from accessing the stream. The affected versions are 1.4.8-4 through 1.5.7-13. This is a local or adjacent network attack that requires the attacker to be able to invoke the vulnerable method with a malicious parameter; no authentication bypass or remote exploitation is involved. A patch is available in version 1.5.7-14 and later.

Affected products

  • Luben zstd-jni 1.4.8-4 through 1.5.7-13

Timeline

  • 2026-09-10: disclosed
  • 2026-08-16: other: Version 1.5.7-14 released with fix (prior to disclosure)

References

Related threats