CVE-2026-106449: falha de baixa gravidade em yawkat lz4-java
yawkat LZ4 Java: LZ4BlockInputStream with stopOnEmptyBlock=false recurses once per empty block, causing StackOverflowError
Publicada em · Atualizada em
8Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 3.7epss 0.3%
probabilidade de exploração
0.3%top 75% das CVEs
exploração observada
nãonenhuma fonte reporta
yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.4, net.jpountz.lz4.LZ4BlockInputStream configured with stopOnEmptyBlock set to false handles each well-formed empty LZ4Block by recursively calling refill(), allowing a long sequence of empty blocks in an attacker-controlled compressed stream to exhaust the decoding thread's stack and throw StackOverflowError. The default stopOnEmptyBlock setting is true and is not affected, and the issue does not cause memory corruption. This issue is fixed in version 1.11.4.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Produtos afetados
yawkat · lz4-javaCVEs relacionadas — yawkat lz4-java
No mesmo produto, das mais perigosas para as menos.
CVE-2025-66566HIGHyawkat LZ4 Java has a possible information leak in Java safe decompressorEPSS 0.6%CVE-2026-59949MEDIUMyawkat LZ4 Java: JVM Crash via Null Byte Array in lz4-java Streaming XXHash JNI (StreamingXXHash32JNI / StreamingXXHash64JNI)EPSS 0.5%CVE-2026-106453MEDIUMyawkat LZ4 Java: LZ4DecompressorWithLength allocates the unvalidated size from the 4-byte length header, so a 5-byte input triggers a 1 GiB allocation and OutOfMemoryErrorEPSS 0.4%CVE-2026-106452MEDIUMyawkat LZ4 Java: LZ4BlockInputStream allocates an unvalidated compressed length from the stream headerEPSS 0.4%CVE-2026-106450MEDIUMyawkat LZ4 Java: LZ4FrameInputStream reallocates block buffers for every frame, allowing CPU and GC amplification from small inputsEPSS 0.4%CVE-2026-106451HIGHyawkat LZ4 Java: Native library extraction to a shared temporary directory is vulnerable to file replacement by another local userEPSS 0.1%