CVE-2022-4899 is a buffer overrun vulnerability in zstd v1.4.10, affecting Facebook's zstandard compression library. An unauthenticated attacker can trigger this by providing an empty string as an argument to the command-line tool, leading to a high-severity denial-of-service (DoS) impact. With a CVSS score of 7.5, this vulnerability is easily exploitable over the network with low attack complexity. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.4.10CPE matchmatch criteria | cpe:2.3:a:facebook:zstandard:1.4.10:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Third-Party Package Updates in Splunk AppDynamics On-Premises Enterprise Console - August 2025
Aug 6, 2025CVE-2022-4899
Apr 11, 2023zstd vulnerable to buffer overrun
Mar 31, 2023A vulnerability was found in zstd v1.4.10 where an attacker can supply empty string as an argument to the command line tool to cause buffer overrun.
Mar 14, 2023zstd: mysql: buffer overrun in util.c
Jul 17, 2022