LZ4 Compression Vulnerability in yawkat Java Product
CVE-2026-106453

5.3MEDIUM

Key Information:

Vendor

Yawkat

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-106453?

The LZ4 Java library prior to version 1.11.2 contains a vulnerability where the LZ4DecompressorWithLength class relies on an unvalidated decompressed length header, allowing an attacker to craft a compressed input that requests an excessive amount of memory, potentially exhausting the Java Virtual Machine's heap space. This issue primarily affects convenience overloads that do not check the destination buffer size, enabling a scenario where an attacker can manipulate memory allocation, posing significant security risks. Users are advised to upgrade to version 1.11.2 or later to mitigate this vulnerability.

Affected Version(s)

lz4-java < 1.11.2

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.