LZ4 Compression Vulnerability in Yawkat's Java Implementation
CVE-2026-106449

3.7LOW

Key Information:

Vendor

Yawkat

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-106449?

Prior to version 1.11.4, Yawkat's LZ4 Java library contains a vulnerability related to the handling of empty LZ4 blocks in a compressed stream. When the 'stopOnEmptyBlock' setting is configured to false, the library allows excessive recursive calls to the refill() method when encountering a sequence of empty blocks. This behavior may lead to a StackOverflowError in the decoding thread, though the default setting remains unaffected as it is set to true. Users are encouraged to update to version 1.11.4 to mitigate this issue.

Affected Version(s)

lz4-java < 1.11.4

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.