CVE-2026-87962
Deferred Deferred - Pending Action

Denial of Service in t-digest via Malformed Serialized Data

Vulnerability report for CVE-2026-87962, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-10

Last updated on: 2026-09-10

Assigner: VulnCheck

Description

t-digest versions 3.1 through 3.3 contain a denial of service vulnerability in MergingDigest.fromBytes that fails to validate length and capacity fields from serialized data. Attackers can supply crafted serialized digests with mismatched header fields to trigger ArrayIndexOutOfBoundsException or NegativeArraySizeException, aborting the parsing thread.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-10
Last Modified
2026-09-10
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-29
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
tdunning t-digest From 3.1 (inc) to 3.3 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1284 The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects t-digest versions 3.1 through 3.3. It involves a denial of service flaw in the MergingDigest.fromBytes method where serialized data is not properly validated. Attackers can craft malicious serialized digests with mismatched header fields, causing ArrayIndexOutOfBoundsException or NegativeArraySizeException, which crashes the parsing thread.

Detection Guidance

To detect this vulnerability, inspect applications using t-digest versions 3.1 through 3.3 for crashes during deserialization of crafted byte arrays. Monitor logs for ArrayIndexOutOfBoundsException or NegativeArraySizeException in threads handling MergingDigest.fromBytes. Check if serialized data from untrusted sources is processed without validation.

Impact Analysis

This vulnerability can cause denial of service by crashing threads processing serialized digests. Systems using t-digest for quantile calculations or statistical aggregations may experience unexpected failures or downtime when malicious input is processed.

Compliance Impact

This vulnerability is a denial-of-service issue that crashes parsing threads via crafted serialized data. It does not directly affect data confidentiality or integrity but could disrupt services processing statistical data, potentially impacting compliance with availability requirements in standards like GDPR (Article 32) or HIPAA (Security Rule).

Mitigation Strategies

Upgrade t-digest to a patched version beyond 3.3. If upgrading is not possible, validate all serialized data length fields before passing to MergingDigest.fromBytes. Ensure no untrusted byte arrays are deserialized without bounds checking.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87962. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart