CVE-2026-85228

Source
https://cve.org/CVERecord?id=CVE-2026-85228
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-85228.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-85228
Published
2026-09-10T17:03:48Z
Modified
2026-09-12T03:47:20Z
Severity
  • 8.8 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Integer overflow in tensor buffer validation in Deep Java Library
Details

An integer overflow in the tensor buffer validation component in Amazon Deep Java Library (DJL) from 0.13.0 through 0.36.0 on all platforms might allow a remote unauthenticated actor to obtain information from adjacent process memory or cause a denial of service via a crafted tensor payload.

To remediate this issue, users should upgrade to version 0.37.0 or above.

Database specific
{
    "cna_assigner": "AMZN",
    "cwe_ids": [
        "CWE-190"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/85xxx/CVE-2026-85228.json"
}
References

Affected packages

Git / github.com/deepjavalibrary/djl

Affected ranges

Type
GIT
Repo
https://github.com/deepjavalibrary/djl
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0.13.0"
        },
        {
            "fixed": "0.36.0"
        }
    ],
    "source": [
        "DESCRIPTION",
        "REFERENCES"
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-85228.json"