# Jansi Library Flaw CVE-2026-8484 Disclosed

Published: 2026-06-16 · Severity: medium
Canonical: https://vorant.io/reports/f04f6656-2651-5e7c-9630-b3745077fa12/jansi-library-flaw-cve-2026-8484-disclosed

> An unpatched heap buffer overflow in the unmaintained jansi JNI ioctl() wrapper can crash Java applications, with no fix expected.

CERT Polska coordinated disclosure of CVE-2026-8484, a heap buffer overflow in the FuseSource jansi library's JNI ioctl() wrapper. The vulnerability stems from a missing size check on the argument array before invoking the native system call, leading to heap corruption and denial-of-service crashes in applications that embed the library.

## Mentioned in this report

- Vulnerabilities: CVE-2026-8484

Source reporting: https://cert.pl/en/posts/2026/06/CVE-2026-8484

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/f04f6656-2651-5e7c-9630-b3745077fa12/jansi-library-flaw-cve-2026-8484-disclosed.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
