CVE-2026-85228
Last modified
CVE-2026-85228 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. An integer overflow in the tensor buffer validation component in Amazon Deep Java Library (DJL) from 0.13.0 through 0.36.0 on all platforms might allow a remote unauthenticated actor to obtain information from adjacent process memory or cause a denial of service via a crafted tensor payload. To remediate this issue, users should upgrade to version 0.37.0 or above..
Description
An integer overflow in the tensor buffer validation component in Amazon Deep Java Library (DJL) from 0.13.0 through 0.36.0 on all platforms might allow a remote unauthenticated actor to obtain information from adjacent process memory or cause a denial of service via a crafted tensor payload. To remediate this issue, users should upgrade to version 0.37.0 or above.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Amazon | Deep Java Library | >= 0.13.0, <= 0.36.0 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-85228?
How severe is CVE-2026-85228?
How do I fix CVE-2026-85228?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-85222A vulnerability has been found in D-Link DNS-340L 1.01B04. A…9.1
- CVE-2026-85223A vulnerability was found in D-Link DNS-340L 1.01B04. Affect…9.9
- CVE-2026-85224A vulnerability was determined in D-Link DNS-320 ShareCenter…9.1
- CVE-2026-85225A vulnerability was identified in code-projects Doctor Appoi…7.3
- CVE-2026-85226MISP contains an authorization flaw in the OnDemand correlat…4.3
- CVE-2026-85227MISP contains a reflected Cross-Site Scripting (XSS) vulnera…6.1
- CVE-2026-85229** UNSUPPORTED WHEN ASSIGNED ** Improper neutralization of i…6.1
- CVE-2026-8523Use after free in Mojo in Google Chrome prior to 148.0.7778.…8.3
- CVE-2026-85230A persistent unsafe URL injection vulnerability exists in th…5.4
- CVE-2026-85234A flaw was found in tftp-hpa. When the `in.tftpd` remap engi…7.5
- CVE-2026-85236A cross-site request forgery (CSRF) vulnerability existed in…8.8
- CVE-2026-85237A vulnerability in MISP's email-based one-time password (OTP…8.1
Are you affected by CVE-2026-85228?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
