LZ4 Compression Vulnerability in Yawkat Java Implementation
CVE-2026-106451
7.3HIGH
What is CVE-2026-106451?
The LZ4 Java implementation by Yawkat, versions 1.7.0 to 1.11.4, contains a vulnerability in the loading mechanism of native libraries. The issue lies in the way temporary .lck files are created using File.createTempFile. A potential attacker can exploit this flaw by creating or replacing the library file in a shared temporary directory before it is loaded by the system. This can lead to unauthorized execution of native code under the context of the victim. Systems relying on secure configurations, such as a private java.io.tmpdir or using Java-only implementations, are not affected by this vulnerability. It is important to upgrade to version 1.11.4, which addresses and mitigates this risk.
Affected Version(s)
lz4-java < 1.11.4
