Jansi Library Flaw CVE-2026-8484 Disclosed
An unpatched heap buffer overflow in the unmaintained jansi JNI ioctl() wrapper can crash Java applications, with no fix expected.
CERT Polska coordinated disclosure of CVE-2026-8484, a heap buffer overflow in the FuseSource jansi library's JNI ioctl() wrapper. The vulnerability stems from a missing size check on the argument array before invoking the native system call, leading to heap corruption and denial-of-service crashes in applications that embed the library.
Mentioned in this report
Vulnerabilities
CVE-2026-8484
Source reporting: https://cert.pl/en/posts/2026/06/CVE-2026-8484
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free