Integer overflow in tensor buffer validation in Deep Java Library
UnratedCVE-2026-85228 · Published Sep 10, 2026
Bulletin ID: 2026-106-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/10/2026 10:00 AM PDT Description: Deep Java Library (DJL) is an open-source, engine-agnostic Java framework for deep learning, developed and maintained by Amazon. AWS identified CVE-2026-85228, an integer overflow in the tensor buffer validation component of DJL on all platforms. A crafted tensor payload declaring a shape whose computed byte size exceeds the 32-bit signed integer range causes the size to wrap, allowing an undersized buffer to pass validation; a subsequent tensor operation then reads out of bounds. If leveraged, a remote, unauthenticated actor could obtain information from adjacent process memory or cause a denial of service. A fix for this issue has been released and we recommend users of DJL upgrade to version 0.37.0 or later. Impacted versions: >=0.13.0 AND <=0.36.0 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
Affected versions
Details and references
- Severity from
- no source yet
More AWS advisories
All AWS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 11 | XML External Entity (XXE) in AWS Advanced JDBC Wrapper RemoteQueryCachePlugin | Unrated | No fix yet |
| Sep 11 | Issue with projen - Path traversal and OS command injection | Unrated | No fix yet |
| Sep 10 | Server-side request forgery in the Session Manager port forwarding functionality in AWS... | Unrated | No fix yet |
| Sep 10 | Missing S3 bucket ownership verification in the AWS Security Agent plugin for... | Unrated | No fix yet |
| Sep 9 | Uncontrolled recursion in the aws-smithy-json unknown-key skip path allows... | Unrated | No fix yet |
| Sep 9 | Issue with awslabs mysql-mcp-server | Unrated | No fix yet |