| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-4v53-57pg-c464 | yawkat LZ4 Java: LZ4BlockInputStream allocates an unvalidated compressed length from the stream header |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 07 Oct 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 07 Oct 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 07 Oct 2026 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Yawkat
Yawkat lz4-java |
|
| Vendors & Products |
Yawkat
Yawkat lz4-java |
Tue, 06 Oct 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.2, net.jpountz.lz4.LZ4BlockInputStream refill() validates that the compressedLen field in a legacy LZ4Block header is nonnegative but allocates a compressed-input buffer of that attacker-controlled size before reading payload data, allowing a header-only stream to request a near-2 GiB allocation and exhaust the JVM heap. Canonical writers emit raw blocks when compression is not smaller than the original block, but vulnerable readers accept non-canonical oversized compressed blocks. This issue is fixed in version 1.11.2. | |
| Title | yawkat LZ4 Java: LZ4BlockInputStream allocates an unvalidated compressed length from the stream header | |
| Weaknesses | CWE-789 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-07T10:45:18.010Z
Reserved: 2026-10-06T16:49:40.591Z
Link: CVE-2026-106452
Updated: 2026-10-07T10:45:14.297Z
Status : Awaiting Analysis
Published: 2026-10-06T20:17:27.317
Modified: 2026-10-07T13:58:29.527
Link: CVE-2026-106452
OpenCVE Enrichment
Updated: 2026-10-07T13:45:06Z
Github GHSA