CVE-2026-87877
Awaiting Analysis Awaiting Analysis - Queue

zstd-jni Stream Class Method Use-After-Free Vulnerability

Vulnerability report for CVE-2026-87877, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-09

Assigner: VulnCheck

Description

zstd-jni versions before 1.5.7-14 fail to validate closed state in setDict, setLongMax, setLevel and setRefMultipleDDicts methods of stream classes. Attackers can call these methods on closed streams to write through freed native pointers, corrupting unrelated objects or crashing the JVM.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-09
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
luben zstd-jni to 1.5.7-14 (exc)
luben zstd-jni 1.5.7-14
luben zstd-jni From 1.3.8-4 (inc) to 1.5.7-13 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-416 The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a use-after-free vulnerability in zstd-jni versions before 1.5.7-14. It occurs when methods like setDict, setLongMax, setLevel, and setRefMultipleDDicts are called on closed streams. The close method frees native pointers but fails to clear a numeric handle field, allowing subsequent calls to write through freed memory. This can corrupt unrelated objects or crash the JVM.

Detection Guidance

Detecting this vulnerability requires checking the version of zstd-jni in use. Use commands like 'find / -name "zstd-jni*.jar" 2>/dev/null' to locate the library, then inspect the version in the JAR filename or manifest. If the version is between 1.3.8-4 and 1.5.7-13, the system is vulnerable.

Impact Analysis

Exploitation requires local access and can lead to memory corruption or JVM crashes. Attackers could corrupt unrelated objects or cause denial-of-service by crashing the application. The impact depends on the application's use of zstd-jni for compression/decompression tasks.

Compliance Impact

This vulnerability could lead to memory corruption or JVM crashes, potentially causing data loss or unauthorized access to sensitive information. For GDPR, this may violate principles of integrity and confidentiality (Article 5). For HIPAA, it could compromise the security of protected health information by allowing unauthorized modifications or access.

Mitigation Strategies

Upgrade zstd-jni to version 1.5.7-14 or later immediately. This patched version includes closed-state guards in methods like setDict, setLongMax, setLevel, and setRefMultipleDDicts to prevent use-after-free issues.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87877. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart