CVE-2026-106450: medium-severity vulnerability in yawkat lz4-java
yawkat LZ4 Java: LZ4FrameInputStream reallocates block buffers for every frame, allowing CPU and GC amplification from small inputs
Published
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.3epss 0.4%
exploitation probability
0.4%top 71% of all CVEs
observed exploitation
nono source reports it
yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.4, net.jpountz.lz4.LZ4FrameInputStream readHeader() allocates two new 4 MiB block buffers whenever a maximum-block-size frame header is read, and the default concatenated-frame mode allows attacker-controlled streams containing many minimal empty frames to trigger roughly 8 MiB of allocation for every 11 input bytes. The stream produces no decompressed output while consuming CPU and garbage-collection time, so decompressed-size limits do not mitigate the issue; readSingleFrame mode is not affected. This issue is fixed in version 1.11.4.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Affected products
yawkat · lz4-javaRelated CVEs — yawkat lz4-java
In the same product, most dangerous first.
CVE-2025-66566HIGHyawkat LZ4 Java has a possible information leak in Java safe decompressorEPSS 0.6%CVE-2026-59949MEDIUMyawkat LZ4 Java: JVM Crash via Null Byte Array in lz4-java Streaming XXHash JNI (StreamingXXHash32JNI / StreamingXXHash64JNI)EPSS 0.5%CVE-2026-106453MEDIUMyawkat LZ4 Java: LZ4DecompressorWithLength allocates the unvalidated size from the 4-byte length header, so a 5-byte input triggers a 1 GiB allocation and OutOfMemoryErrorEPSS 0.4%CVE-2026-106452MEDIUMyawkat LZ4 Java: LZ4BlockInputStream allocates an unvalidated compressed length from the stream headerEPSS 0.4%CVE-2026-106449LOWyawkat LZ4 Java: LZ4BlockInputStream with stopOnEmptyBlock=false recurses once per empty block, causing StackOverflowErrorEPSS 0.3%CVE-2026-106451HIGHyawkat LZ4 Java: Native library extraction to a shared temporary directory is vulnerable to file replacement by another local userEPSS 0.1%