Article

    Cyber News / Article / Vulnerability in jansi library

    Vulnerability in jansi library
    CE
    CERT Polska-2026-06-16

    Vulnerability in jansi library

    CERT Polska has received a report about vulnerability in FuseSource jansi library and participated in coordination of its disclosure.

    The vulnerabilityCVE-2026-8484: A heap buffer overflow vulnerability exists in the jansi JNI (Java Native Interface)ioctl()wrapper due to a lack of size verification for the argument array before the system call. This can lead to heap corruption and application crashes (DoS).

    All versions are believed to be vulnerable. This project is unmaintained at the time of CVE assignment.

    We thank Michał Majchrowicz and Marcin Wyczechowski (AFINE Team) for the responsible vulnerability report.

    Original source