Skip to content
AWSAWS-2026-106

Integer overflow in tensor buffer validation in Deep Java Library

UnratedCVE-2026-85228 · Published Sep 10, 2026

Bulletin ID: 2026-106-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/10/2026 10:00 AM PDT Description: Deep Java Library (DJL) is an open-source, engine-agnostic Java framework for deep learning, developed and maintained by Amazon. AWS identified CVE-2026-85228, an integer overflow in the tensor buffer validation component of DJL on all platforms. A crafted tensor payload declaring a shape whose computed byte size exceeds the 32-bit signed integer range causes the size to wrap, allowing an undersized buffer to pass validation; a subsequent tensor operation then reads out of bounds. If leveraged, a remote, unauthenticated actor could obtain information from adjacent process memory or cause a denial of service. A fix for this issue has been released and we recommend users of DJL upgrade to version 0.37.0 or later. Impacted versions: >=0.13.0 AND <=0.36.0 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.

AWS advisory

Affected versions

The source does not list versions here. See the source advisory for affected products and fixes.
Details and references

More AWS advisories

All AWS

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.