CVE-2026-106453: medium-severity vulnerability in yawkat lz4-java
yawkat LZ4 Java: LZ4DecompressorWithLength allocates the unvalidated size from the 4-byte length header, so a 5-byte input triggers a 1 GiB allocation and OutOfMemoryError
Published · Updated
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.3epss 0.4%
exploitation probability
0.4%top 71% of all CVEs
observed exploitation
nono source reports it
yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.2, LZ4DecompressorWithLength uses getDecompressedLength to trust the four-byte decompressed-length header before validating the compressed input, allowing a five-byte attacker-supplied input whose header declares a large output size to request up to approximately 2 GiB and exhaust the JVM heap. Convenience overloads backed by LZ4FastDecompressor or LZ4SafeDecompressor allocate the untrusted size, while overloads that write to a caller-provided destination buffer are not affected because the caller controls the destination size. This issue is fixed in version 1.11.2.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Affected products
yawkat · lz4-javaRelated CVEs — yawkat lz4-java
In the same product, most dangerous first.
CVE-2025-66566HIGHyawkat LZ4 Java has a possible information leak in Java safe decompressorEPSS 0.6%CVE-2026-59949MEDIUMyawkat LZ4 Java: JVM Crash via Null Byte Array in lz4-java Streaming XXHash JNI (StreamingXXHash32JNI / StreamingXXHash64JNI)EPSS 0.5%CVE-2026-106452MEDIUMyawkat LZ4 Java: LZ4BlockInputStream allocates an unvalidated compressed length from the stream headerEPSS 0.4%CVE-2026-106450MEDIUMyawkat LZ4 Java: LZ4FrameInputStream reallocates block buffers for every frame, allowing CPU and GC amplification from small inputsEPSS 0.4%CVE-2026-106449LOWyawkat LZ4 Java: LZ4BlockInputStream with stopOnEmptyBlock=false recurses once per empty block, causing StackOverflowErrorEPSS 0.3%CVE-2026-106451HIGHyawkat LZ4 Java: Native library extraction to a shared temporary directory is vulnerable to file replacement by another local userEPSS 0.1%