PT-2026-107242 · Unknown · Yawkat Lz4 Java
CVE-2026-106453
·
Published
2026-10-06
·
Updated
2026-10-07
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
yawkat LZ4 Java versions prior to 1.11.2
Description
The
LZ4DecompressorWithLength component trusts the four-byte decompressed-length header via the getDecompressedLength() function before validating the compressed input. This allows an attacker to provide a five-byte input with a header declaring a large output size, potentially requesting up to 2 GiB and exhausting the JVM heap. This issue affects convenience overloads backed by LZ4FastDecompressor or LZ4SafeDecompressor that allocate the untrusted size. Overloads writing to a caller-provided destination buffer are not affected.Recommendations
Update yawkat LZ4 Java to version 1.11.2.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Yawkat Lz4 Java