CVE-2026-106449: low-severity vulnerability in yawkat lz4-java
yawkat LZ4 Java: LZ4BlockInputStream with stopOnEmptyBlock=false recurses once per empty block, causing StackOverflowError
Published · Updated
8Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 3.7epss 0.3%
exploitation probability
0.3%top 75% of all CVEs
observed exploitation
nono source reports it
yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.4, net.jpountz.lz4.LZ4BlockInputStream configured with stopOnEmptyBlock set to false handles each well-formed empty LZ4Block by recursively calling refill(), allowing a long sequence of empty blocks in an attacker-controlled compressed stream to exhaust the decoding thread's stack and throw StackOverflowError. The default stopOnEmptyBlock setting is true and is not affected, and the issue does not cause memory corruption. This issue is fixed in version 1.11.4.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Affected products
yawkat · lz4-javaRelated CVEs — yawkat lz4-java
In the same product, most dangerous first.
CVE-2025-66566HIGHyawkat LZ4 Java has a possible information leak in Java safe decompressorEPSS 0.6%CVE-2026-59949MEDIUMyawkat LZ4 Java: JVM Crash via Null Byte Array in lz4-java Streaming XXHash JNI (StreamingXXHash32JNI / StreamingXXHash64JNI)EPSS 0.5%CVE-2026-106453MEDIUMyawkat LZ4 Java: LZ4DecompressorWithLength allocates the unvalidated size from the 4-byte length header, so a 5-byte input triggers a 1 GiB allocation and OutOfMemoryErrorEPSS 0.4%CVE-2026-106452MEDIUMyawkat LZ4 Java: LZ4BlockInputStream allocates an unvalidated compressed length from the stream headerEPSS 0.4%CVE-2026-106450MEDIUMyawkat LZ4 Java: LZ4FrameInputStream reallocates block buffers for every frame, allowing CPU and GC amplification from small inputsEPSS 0.4%CVE-2026-106451HIGHyawkat LZ4 Java: Native library extraction to a shared temporary directory is vulnerable to file replacement by another local userEPSS 0.1%