LZ4 Compression Vulnerability in yawkat Java Product
CVE-2026-106453
5.3MEDIUM
What is CVE-2026-106453?
The LZ4 Java library prior to version 1.11.2 contains a vulnerability where the LZ4DecompressorWithLength class relies on an unvalidated decompressed length header, allowing an attacker to craft a compressed input that requests an excessive amount of memory, potentially exhausting the Java Virtual Machine's heap space. This issue primarily affects convenience overloads that do not check the destination buffer size, enabling a scenario where an attacker can manipulate memory allocation, posing significant security risks. Users are advised to upgrade to version 1.11.2 or later to mitigate this vulnerability.
Affected Version(s)
lz4-java < 1.11.2
