Memory Allocation Issue in LZ4 Compression by Yawkat
CVE-2026-106452

5.3MEDIUM

Key Information:

Vendor

Yawkat

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-106452?

A vulnerability in the LZ4 Java library prior to version 1.11.2 allows an attacker to create a header-only compressed stream that requests a massive memory allocation, potentially exhausting the Java Virtual Machine (JVM) heap. This occurs due to insufficient validation of the size specified in the LZ4Block header associated with legacy compression formats. As a result, it enables adversaries to influence the system's memory management leading to denial-of-service conditions. Users are encouraged to update to version 1.11.2 or later to mitigate this risk and enhance the security of their applications.

Affected Version(s)

lz4-java < 1.11.2

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.