{"id":"CVE-2026-106452","title":"yawkat LZ4 Java provides LZ4 compression for Java","summary":"yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.2, net.jpountz.lz4.LZ4BlockInputStream refill() validates that the compressedLen field in a legacy LZ4Block header is nonnegative but allocates a compressed-input buffer of…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","cwe":["CWE-789","CWE-770"],"vendor":"yawkat","product":"lz4-java","affected":["lz4-java < 1.11.2"],"published":"2026-10-06","updated":"2026-10-07","sourceUpdated":"2026-10-07T13:58:29.527","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-106452","references":[{"url":"https://github.com/yawkat/lz4-java/commit/bb83dd16163cdb71231af06b0a5651881148a634","label":"security-advisories@github.com"},{"url":"https://github.com/yawkat/lz4-java/releases/tag/v1.11.2","label":"security-advisories@github.com"},{"url":"https://github.com/yawkat/lz4-java/security/advisories/GHSA-4v53-57pg-c464","label":"security-advisories@github.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-106452.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-106452"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2547136"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-106452"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106452"},{"url":"https://github.com/advisories/GHSA-4v53-57pg-c464"}],"tags":["nvd","cve.org","csaf","vex","red-hat","ghsa","maven"],"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-10-07T10:45:08.750360Z"},"ingestedAt":"2026-10-06T20:16:42.474Z","aliases":["GHSA-4v53-57pg-c464"],"ecosystem":"maven","patched":["at.yawk.lz4:lz4-java 1.11.2"],"slug":"CVE-2026-106452","body":"## Overview\n\nyawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.2, net.jpountz.lz4.LZ4BlockInputStream refill() validates that the compressedLen field in a legacy LZ4Block header is nonnegative but allocates a compressed-input buffer of that attacker-controlled size before reading payload data, allowing a header-only stream to request a near-2 GiB allocation and exhaust the JVM heap. Canonical writers emit raw blocks when compression is not smaller than the original block, but vulnerable readers accept non-canonical oversized compressed blocks. This issue is fixed in version 1.11.2.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Red Hat build of Apache Camel for Spring Boot 4, Red Hat build of Debezium 3, Red Hat Enterprise Linux 9, Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 8, Red Hat JBoss Enterprise Application Platform Expansion Pack, … · no fix planned: Red Hat Fuse 7, Red Hat build of Apache Camel for Spring Boot 4, Red Hat build of Debezium 3, Red Hat Enterprise Linux 9, … · updated 2026-10-07 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-106452.json)\n\n## Package advisory (CVE-2026-106452)\n\nAffected packages:\n\n- `at.yawk.lz4:lz4-java <= 1.11.1`\n- `org.lz4:lz4-java <= 1.8.1`\n\nPatched in:\n\n- `at.yawk.lz4:lz4-java 1.11.2`\n\nSource: https://github.com/advisories/GHSA-4v53-57pg-c464","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}