Description
An integer overflow in the tensor buffer validation component in Amazon Deep Java Library (DJL) from 0.13.0 through 0.36.0 on all platforms might allow a remote unauthenticated actor to obtain information from adjacent process memory or cause a denial of service via a crafted tensor payload.



To remediate this issue, users should upgrade to version 0.37.0 or above.
Published: 2026-09-10
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Upgrade
AI Analysis

Impact

An integer overflow exists in the tensor buffer validation component of Amazon Deep Java Library. When a malicious actor supplies a malformed tensor payload, the overflow can lead to reading data from adjacent process memory, exposing potentially sensitive information, and it can also trigger a crash, resulting in a denial of service. The flaw is an instance of CWE-190, Integer Overflow or Wraparound, affecting the library's ability to correctly bound internal buffer sizes.

Affected Systems

Amazon Deep Java Library community releases from version 0.13.0 through 0.36.0 on all supported platforms are affected by this vulnerability.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, suggesting that active exploitation is currently unclear. However, a remote unauthenticated attacker can send a crafted tensor payload to any DJL-enabled application, potentially retrieving information from adjacent memory or causing a denial of service. required, making the risk significant for deployments that expose DJL functionality over a network.

Generated by OpenCVE AI on September 11, 2026 at 00:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Deep Java Library to version 0.37.0 or later.
  • If an upgrade cannot be performed immediately, run DJL inside a sandboxed or containerized environment with strict memory and process isolation to contain any memory exposure or crash.
  • Validate all incoming tensor payloads before passing them to DJL, ensuring that payload sizes and dimensions remain within safe bounds to prevent the integer overflow.

Generated by OpenCVE AI on September 11, 2026 at 00:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Description An integer overflow in the tensor buffer validation component in Amazon Deep Java Library (DJL) from 0.13.0 through 0.36.0 on all platforms might allow a remote unauthenticated actor to obtain information from adjacent process memory or cause a denial of service via a crafted tensor payload. To remediate this issue, users should upgrade to version 0.37.0 or above.
Title Integer overflow in tensor buffer validation in Deep Java Library
First Time appeared Amazon
Amazon deep Java Library
Weaknesses CWE-190
CPEs cpe:2.3:a:amazon:deep_java_library:*:*:*:*:*:*:*:*
Vendors & Products Amazon
Amazon deep Java Library
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'}

cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Amazon Deep Java Library
cve-icon MITRE

Status: PUBLISHED

Assigner: AMZN

Published:

Updated: 2026-09-10T18:20:34.948Z

Reserved: 2026-09-03T14:46:41.766Z

Link: CVE-2026-85228

cve-icon Vulnrichment

Updated: 2026-09-10T18:20:31.643Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-10T17:17:06.437

Modified: 2026-09-10T19:54:25.810

Link: CVE-2026-85228

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T07:45:06Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound