Product
facebook zstandard
4 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2022-4899
CVE-2021-24032
CVE-2021-24031
CVE-2019-11922
all versions
A vulnerability was found in zstd v1.4.10, where an attacker can supply empty string as an argument to the command line tool to ca
>= 1.4.1 and < 1.4.9
Beginning in v1.4.1 and prior to v1.4.9, due to an incomplete fix for CVE-2021-24031, the Zstandard command-line utility created o
< 1.4.1
In the Zstandard command-line utility prior to v1.4.1, output files were created with default permissions. Correct file permission
< 1.3.8
A race condition in the one-pass compression functions of Zstandard prior to version 1.3.8 could allow an attacker to write bytes