{"id":"CVE-2026-89045","summary":"zstd-jni 1.4.8-4 through 1.5.7-13 Denial of Service via Negative Length","details":"zstd-jni versions 1.4.8-4 through 1.5.7-13 fail to validate negative length parameters in ZstdInputStreamNoFinalizer.read(), allowing attackers to trigger infinite loops. Attackers can pass negative length values to cause the read method to spin indefinitely while holding the stream monitor, blocking all other threads from accessing the stream.","aliases":["GHSA-9jx2-gfp9-phfm"],"modified":"2026-09-12T08:07:34.280367Z","published":"2026-09-10T17:39:34.866Z","database_specific":{"cwe_ids":["CWE-835"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89045.json","cna_assigner":"VulnCheck"},"references":[{"type":"WEB","url":"https://repo1.maven.org/maven2/com/github/luben/zstd-jni/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89045.json"},{"type":"ADVISORY","url":"https://github.com/luben/zstd-jni/releases/tag/v1.5.7-14"},{"type":"ADVISORY","url":"https://github.com/luben/zstd-jni/security/advisories/GHSA-9jx2-gfp9-phfm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89045"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/zstd-jni-1.4.8-4-through-1.5.7-13-denial-of-service-via-negative-length"},{"type":"FIX","url":"https://github.com/luben/zstd-jni/commit/dd08685ef913a32e76fb27f43470035c06758646"},{"type":"PACKAGE","url":"https://github.com/luben/zstd-jni"},{"type":"ARTICLE","url":"https://github.com/luben/zstd-jni/blob/v1.5.7-13/src/main/java/com/github/luben/zstd/ZstdInputStreamNoFinalizer.java#L133"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/luben/zstd-jni","events":[{"introduced":"84e41c02f4dcb79a2b502e4143f89437d640c1b7"},{"fixed":"3216860eea289fbbae0b191c0a4fd8b72dad949c"}],"database_specific":{"extracted_events":[{"introduced":"1.4.8-4"},{"fixed":"1.5.7-14"}],"source":"AFFECTED_FIELD"}}],"versions":["v1.5.7-13","v1.5.7-12","v1.5.7-11","v1.5.7-9","v1.5.7-8","v1.5.7-7","v1.5.7-6","v1.5.7-5","v1.5.7-4","v1.5.7-3","v1.5.7-2","v1.5.7-1","v1.5.6-10","v1.5.6-9","v1.5.6-8","v1.5.6-7","v1.5.6-6","v1.5.6-5","v1.5.6-4","v1.5.6-3","v1.5.6-2","v1.5.6-1","v1.5.5-11","v1.5.5-10","v1.5.5-9","b1.5.5-9","v1.5.5-8","v1.5.5-7","v1.5.5-6","v.1.5.5-5","v1.5.5-3","v1.5.5-2","v1.5.5-1","v1.5.4-2","v1.5.4-1","c1.5.2-5","v1.5.2-3","v1.5.2-2","v1.5.2-1","v1.5.1-1","v1.5.0-5","v1.5.0-4","v1.5.0-3","v1.5.0-2","v1.5.0-1","v1.4.9-5","v1.4.9-4","v1.4.9-3","v1.4.9-2","v1.4.9-1","v1.4.8-7","v1.4.8-6","v1.4.8-5","v1.4.8-4"],"database_specific":{"vanir_signatures":[{"digest":{"function_hash":"319696483832917712384682231278816072707","length":525},"id":"CVE-2026-89045-44dbbae1","signature_type":"Function","signature_version":"v1","source":"https://github.com/luben/zstd-jni/commit/3216860eea289fbbae0b191c0a4fd8b72dad949c","target":{"file":"src/main/native/jni_zstd.c","function":"Java_com_github_luben_zstd_Zstd_getDirectByteBufferFrameContentSize"},"deprecated":false},{"digest":{"line_hashes":["242983979289756636978174893894911169283","157823411836278810979700492519583258858","47982388172284482667079231190836641912","142002538935986523140505977783435642687","70654406038950244899492554068964697791","256841266079176367404669460587415964017","136130365917502750732790875301653462261","307914870517560413069750160813139035083","70654406038950244899492554068964697791","256841266079176367404669460587415964017","136130365917502750732790875301653462261","307914870517560413069750160813139035083"],"threshold":0.9},"id":"CVE-2026-89045-cf1cd55a","signature_type":"Line","signature_version":"v1","source":"https://github.com/luben/zstd-jni/commit/3216860eea289fbbae0b191c0a4fd8b72dad949c","target":{"file":"src/main/native/jni_zstd.c"},"deprecated":false},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/luben/zstd-jni/commit/3216860eea289fbbae0b191c0a4fd8b72dad949c","target":{"file":"src/main/native/jni_zstd.c","function":"Java_com_github_luben_zstd_Zstd_findDirectByteBufferFrameCompressedSize"},"deprecated":false,"digest":{"function_hash":"6130561471615133004258603361745015963","length":503},"id":"CVE-2026-89045-e402cad3"},{"source":"https://github.com/luben/zstd-jni/commit/3216860eea289fbbae0b191c0a4fd8b72dad949c","target":{"file":"src/main/native/jni_zstd.c","function":"Java_com_github_luben_zstd_Zstd_decompressedDirectByteBufferSize"},"deprecated":false,"digest":{"length":552,"function_hash":"243452810049814927721413726162029308560"},"id":"CVE-2026-89045-e43e017d","signature_type":"Function","signature_version":"v1"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89045.json","vanir_signatures_modified":"2026-09-12T08:07:34Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}]}