CVE-2026-90560
CVE-2026-90560: 1 tracked advisory record across Red Hat. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Red Hat
1 advisory- Advisory severityHigh8.2
High [CVE-2026-90560] Denial of Service via out-of-bounds read in ZstdDictDecompress
CVE-2026-90560Source published Source updated
Denial of Service via out-of-bounds read in ZstdDictDecompress. Red Hat rates this important (CVSS 8.2). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:71675 with package zstd-jni. Affected products named by the advisory: Exploit Intelligence; OpenShift Developer Tools and Services; Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; and 10 more.
- Related products — impact not confirmed
- Exploit Intelligence
- OpenShift Developer Tools and Services
- Red Hat build of Apache Camel 4 for Quarkus 3
- Red Hat build of Apache Camel for Spring Boot 4
10 more entries in the full advisory.
- Source-reported affected versions
- 1.2.0
- 1.5.7-13
- Source-reported fixed versions
- zstd-jni
- RHSA-2026:71675
- Mitigation guidance
- Until a fixed update is available, applications should validate that dictionary offset and length values are non-negative and that the requested range does not exceed the dictionary array. Apply product updates containing zstd-jni 1.5.7-14 or a Red Hat backport of the fix when available.
Android app · Google Play
Monitor future Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.