Fedora Account System
Red Hat Associate
Red Hat Customer
zstd-jni versions before 1.5.7-14 fail to validate offset and length parameters in the ZstdDictCompress constructor, allowing out-of-bounds memory reads. Attackers can supply untrusted offset or length values to read native heap memory into the compression dictionary, typically causing JVM crashes.
This issue has been addressed in the following products: Red Hat Build of Apache Camel 3.33 for Quarkus 3.33.3.SP2 Via RHSA-2026:70257 https://access.redhat.com/errata/RHSA-2026:70257
This issue has been addressed in the following products: Red Hat build of Apache Camel 4.18.4 for Spring Boot 3.5.16 Via RHSA-2026:71675 https://access.redhat.com/errata/RHSA-2026:71675