CVE-2026-85228: Integer overflow in tensor buffer validation in Deep Java Library
An integer overflow in the tensor buffer validation component in Amazon Deep Java Library (DJL) from 0.13.0 through 0.36.0 on all platforms might allow a remote unauthenticated actor to obtain information from adjacent process memory or cause a denial of service via a crafted tensor payload.
To remediate this issue, users should upgrade to version 0.37.0 or above.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Amazon Deep Java Library (DJL)to a version that resolves this vulnerability.Fixed in 0.37.0
Event History
Frequently Asked Questions
Who can exploit this issue?
A remote unauthenticated actor can exploit the issue by supplying a crafted tensor payload to an affected DJL deployment. The issue affects DJL versions 0.13.0 through 0.36.0 on all platforms.
Are confidentiality and availability affected?
Yes. Successful exploitation might disclose information from adjacent process memory or cause a denial of service; the provided severity vector indicates high confidentiality and availability impact.
What is the recommended remediation?
Upgrade Amazon Deep Java Library (DJL) to version 0.37.0 or later.