An integer overflow in the tensor buffer validation component in Amazon Deep Java Library (DJL) from 0.13.0 through 0.36.0 on all platforms might allow a remote unauthenticated actor to obtain information from adjacent process memory or cause a denial of service via a crafted tensor payload.
To remediate this issue, users should upgrade to version 0.37.0 or above.
To remediate this issue, users should upgrade to version 0.37.0 or above.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 10 Sep 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An integer overflow in the tensor buffer validation component in Amazon Deep Java Library (DJL) from 0.13.0 through 0.36.0 on all platforms might allow a remote unauthenticated actor to obtain information from adjacent process memory or cause a denial of service via a crafted tensor payload. To remediate this issue, users should upgrade to version 0.37.0 or above. | |
| Title | Integer overflow in tensor buffer validation in Deep Java Library | |
| First Time appeared |
Amazon
Amazon deep Java Library |
|
| Weaknesses | CWE-190 | |
| CPEs | cpe:2.3:a:amazon:deep_java_library:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Amazon
Amazon deep Java Library |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2026-09-10T18:20:34.948Z
Reserved: 2026-09-03T14:46:41.766Z
Link: CVE-2026-85228
No data.
Status : Received
Published: 2026-09-10T17:17:06.437
Modified: 2026-09-10T17:17:06.437
Link: CVE-2026-85228
No data.
OpenCVE Enrichment
No data.
Weaknesses