Memory Allocation Issue in LZ4 Compression by Yawkat
CVE-2026-106452
5.3MEDIUM
What is CVE-2026-106452?
A vulnerability in the LZ4 Java library prior to version 1.11.2 allows an attacker to create a header-only compressed stream that requests a massive memory allocation, potentially exhausting the Java Virtual Machine (JVM) heap. This occurs due to insufficient validation of the size specified in the LZ4Block header associated with legacy compression formats. As a result, it enables adversaries to influence the system's memory management leading to denial-of-service conditions. Users are encouraged to update to version 1.11.2 or later to mitigate this risk and enhance the security of their applications.
Affected Version(s)
lz4-java < 1.11.2
