PT-2026-107242 · Unknown · Yawkat Lz4 Java

CVE-2026-106453

·

Published

2026-10-06

·

Updated

2026-10-07

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions yawkat LZ4 Java versions prior to 1.11.2
Description The LZ4DecompressorWithLength component trusts the four-byte decompressed-length header via the getDecompressedLength() function before validating the compressed input. This allows an attacker to provide a five-byte input with a header declaring a large output size, potentially requesting up to 2 GiB and exhausting the JVM heap. This issue affects convenience overloads backed by LZ4FastDecompressor or LZ4SafeDecompressor that allocate the untrusted size. Overloads writing to a caller-provided destination buffer are not affected.
Recommendations Update yawkat LZ4 Java to version 1.11.2.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-106453
GHSA-6CX8-RJF8-PR8G

Affected Products

Yawkat Lz4 Java