LZ4 Compression Vulnerability in Yawkat's Java Implementation
CVE-2026-106449
3.7LOW
What is CVE-2026-106449?
Prior to version 1.11.4, Yawkat's LZ4 Java library contains a vulnerability related to the handling of empty LZ4 blocks in a compressed stream. When the 'stopOnEmptyBlock' setting is configured to false, the library allows excessive recursive calls to the refill() method when encountering a sequence of empty blocks. This behavior may lead to a StackOverflowError in the decoding thread, though the default setting remains unaffected as it is set to true. Users are encouraged to update to version 1.11.4 to mitigate this issue.
Affected Version(s)
lz4-java < 1.11.4
