Hi,
The following vulnerability was published for zstd-jni-java.
CVE-2026-90852[0]:
| A vulnerability has been found in luben zstd-jni up to 1.5.7-13.
| This vulnerability affects the function ZstdCompressCtx.loadDict of
| the file ZstdCompressCtx.java of the component Dictionary Sharing.
| Such manipulation leads to use after free. The attack can be
| executed remotely. The exploit has been disclosed to the public and
| may be used. Upgrading to version 1.5.7-14 is able to resolve this
| issue. The name of the patch is
| a560131d7834598afd9cea6b7c107bc88e915936. The affected component
| should be upgraded. The vendor was contacted early, responded in a
| very professional manner and quickly released a fixed version of the
| affected product.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-90852
https://www.cve.org/CVERecord?id=CVE-2026-90852
[1] https://github.com/luben/zstd-jni/issues/404
[2] https://github.com/luben/zstd-jni/commit/a560131d7834598afd9cea6b7c107bc88e915936
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore