LZ4 Compression Vulnerability in Yawkat Java Implementation
CVE-2026-106451

7.3HIGH

Key Information:

Vendor

Yawkat

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-106451?

The LZ4 Java implementation by Yawkat, versions 1.7.0 to 1.11.4, contains a vulnerability in the loading mechanism of native libraries. The issue lies in the way temporary .lck files are created using File.createTempFile. A potential attacker can exploit this flaw by creating or replacing the library file in a shared temporary directory before it is loaded by the system. This can lead to unauthorized execution of native code under the context of the victim. Systems relying on secure configurations, such as a private java.io.tmpdir or using Java-only implementations, are not affected by this vulnerability. It is important to upgrade to version 1.11.4, which addresses and mitigates this risk.

Affected Version(s)

lz4-java < 1.11.4

References

CVSS V4

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.