Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-106449— yawkat LZ4 Java: LZ4BlockInputStream with stopOnEmptyBlock=false recurses once per empty block, causing StackOverflowError

Quick assessment

Affected
yawkat lz4-java
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

yawkat LZ4 Java 为 Java 提供了 LZ4 压缩支持。在版本 1.11.4 之前,当 被配置为将 设置为 时,会对每个格式正确的空 LZ4Block 递归调用 方法进行处理。攻击者通过在可控的压缩数据流中插入大量空块,可耗尽解码线程的栈空间,从而引发 (栈溢出错误)。 默认情况下, 的配置值为 ,因此不受此漏洞影响。此外,该问题不会导致内存损坏。此问题已在版本 1.11.4 中得到修复。

CVSS 3.7 · Low

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 1

VendorProduct Version RangeStatus
yawkat lz4-java < 1.11.4 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-106449

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
yawkat LZ4 Java: LZ4BlockInputStream with stopOnEmptyBlock=false recurses once per empty block, causing StackOverflowError
Source: CVE Program / CVE List V5
Vulnerability Description
yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.4, net.jpountz.lz4.LZ4BlockInputStream configured with stopOnEmptyBlock set to false handles each well-formed empty LZ4Block by recursively calling refill(), allowing a long sequence of empty blocks in an attacker-controlled compressed stream to exhaust the decoding thread's stack and throw StackOverflowError. The default stopOnEmptyBlock setting is true and is not affected, and the issue does not cause memory corruption. This issue is fixed in version 1.11.4.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
未经控制的递归
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
yawkat lz4-java < 1.11.4 -

II. Public POCs for CVE-2026-106449

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-106449

请登录查看更多情报信息。

Other References for CVE-2026-106449 (3)

Same Patch Batch · yawkat · 2026-10-06 · 5 CVEs total

CVE-2026-106451 7.3 HIGH yawkat LZ4 Java: Native library extraction to a shared temporary directory is vulnerable t
CVE-2026-106452 5.3 MEDIUM yawkat LZ4 Java: LZ4BlockInputStream allocates an unvalidated compressed length from the s
CVE-2026-106450 5.3 MEDIUM yawkat LZ4 Java: LZ4FrameInputStream reallocates block buffers for every frame, allowing C
CVE-2026-106453 5.3 MEDIUM yawkat LZ4 Java: LZ4DecompressorWithLength allocates the unvalidated size from the 4-byte

IV. Related Vulnerabilities

V. Comments for CVE-2026-106449

No comments yet


Leave a comment