---
id: CVE-2026-106449
title: yawkat LZ4 Java provides LZ4 compression for Java
summary: >-
  yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.4,
  net.jpountz.lz4.LZ4BlockInputStream configured with stopOnEmptyBlock set to
  false handles each well-formed empty LZ4Block by recursively calling refill(),
  allowing a lon…
severity: low
cvss: 3.7
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-674
vendor: yawkat
product: lz4-java
affected:
  - lz4-java < 1.11.4
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T20:17:26.887'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-106449'
references:
  - url: >-
      https://github.com/yawkat/lz4-java/commit/c8ebf97d504fb34434fda46fc761e8202570e0d8
    label: security-advisories@github.com
  - url: 'https://github.com/yawkat/lz4-java/releases/tag/v1.11.4'
    label: security-advisories@github.com
  - url: 'https://github.com/yawkat/lz4-java/security/advisories/GHSA-343h-94h5-c4wr'
    label: security-advisories@github.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T20:16:42.480Z'
---

## Overview

yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.4, net.jpountz.lz4.LZ4BlockInputStream configured with stopOnEmptyBlock set to false handles each well-formed empty LZ4Block by recursively calling refill(), allowing a long sequence of empty blocks in an attacker-controlled compressed stream to exhaust the decoding thread's stack and throw StackOverflowError. The default stopOnEmptyBlock setting is true and is not affected, and the issue does not cause memory corruption. This issue is fixed in version 1.11.4.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
