CVE-2026-85228

Summary

An integer overflow in the tensor buffer validation component in Amazon Deep Java Library (DJL) from 0.13.0 through 0.36.0 on all platforms might allow a remote unauthenticated actor to obtain information from adjacent process memory or cause a denial of service via a crafted tensor payload.

To remediate this issue, users should upgrade to version 0.37.0 or above.

Affected Software

VendorProductVersion RangeStatus
AmazonDeep Java Library0.13.0 <= 0.36.0affected

Weaknesses

  • CWE-190: CWE-190 Integer overflow or wraparound

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References