SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-85228

CRITICAL · CVSS 9.1 EPSS 0.38% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-10 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

An integer overflow vulnerability in the tensor buffer validation component of the Amazon Deep Java Library could allow remote unauthenticated attackers to access adjacent process memory or trigger a denial of service through specially crafted tensor payloads. Organizations utilizing versions 0.13.0 to 0.36.0 of this library should prioritize upgrading to version 0.37.0 or later to mitigate the risk of exploitation. This critical vulnerability poses significant security risks, particularly for applications relying on the affected library for processing tensor data.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-85228
Severity
CRITICAL
CVSS
9.1
EPSS
0.38%
Java

Original NVD Description

An integer overflow in the tensor buffer validation component in Amazon Deep Java Library (DJL) from 0.13.0 through 0.36.0 on all platforms might allow a remote unauthenticated actor to obtain information from adjacent process memory or cause a denial of service via a crafted tensor payload. To remediate this issue, users should upgrade to version 0.37.0 or above.