To remediate this issue, users should upgrade to version 0.37.0 or above.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 10 Sep 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 10 Sep 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An integer overflow in the tensor buffer validation component in Amazon Deep Java Library (DJL) from 0.13.0 through 0.36.0 on all platforms might allow a remote unauthenticated actor to obtain information from adjacent process memory or cause a denial of service via a crafted tensor payload. To remediate this issue, users should upgrade to version 0.37.0 or above. | |
| Title | Integer overflow in tensor buffer validation in Deep Java Library | |
| First Time appeared |
Amazon
Amazon deep Java Library |
|
| Weaknesses | CWE-190 | |
| CPEs | cpe:2.3:a:amazon:deep_java_library:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Amazon
Amazon deep Java Library |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2026-09-10T18:20:34.948Z
Reserved: 2026-09-03T14:46:41.766Z
Link: CVE-2026-85228
Updated: 2026-09-10T18:20:31.643Z
Status : Awaiting Analysis
Published: 2026-09-10T17:17:06.437
Modified: 2026-09-10T19:54:25.810
Link: CVE-2026-85228
No data.
OpenCVE Enrichment
Updated: 2026-09-11T00:15:17Z