Description
yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.2, LZ4DecompressorWithLength uses getDecompressedLength to trust the four-byte decompressed-length header before validating the compressed input, allowing a five-byte attacker-supplied input whose header declares a large output size to request up to approximately 2 GiB and exhaust the JVM heap. Convenience overloads backed by LZ4FastDecompressor or LZ4SafeDecompressor allocate the untrusted size, while overloads that write to a caller-provided destination buffer are not affected because the caller controls the destination size. This issue is fixed in version 1.11.2.
Published: 2026-10-06
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service via memory exhaustion
Action: Apply Patch
AI Analysis

Impact

A flaw in the LZ4DecompressorWithLength implementation trusts the four‑byte decompressed‑length header before validating the compressed data. An attacker can craft a five‑byte payload whose header requests a large output size, causing the library to allocate up to roughly 2 GiB of memory and trigger an OutOfMemoryError. This results in a denial of service by crashing the JVM process that is decompressing the data. The weakness is an input validation defect (CWE‑789).

Affected Systems

The issue affects the yawkat lz4‑java library in all releases prior to version 1.11.2. Any Java application that uses LZ4DecompressorWithLength to decompress data from untrusted sources is vulnerable; overloads that write directly to a caller‑provided buffer are not impacted because the caller controls the destination size.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. No EPSS score is available, and the vulnerability is not listed in CISA KEV. The likely attack vector is via manipulated compressed input supplied to an application that uses the affected library, which could be local or remote depending on the application’s exposure. An attacker who can supply such input will cause the victim JVM to exhaust memory, potentially disrupting service availability.

Generated by OpenCVE AI on October 7, 2026 at 01:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to lz4‑java 1.11.2 or later, which removes the unchecked allocation.
  • If an upgrade is not immediately possible, perform pre‑decompression validation to verify that the declared output size does not exceed a safe threshold and reject the input if it does.
  • Configure application and JVM settings to limit memory usage and catch OutOfMemoryError, so that a crash does not compromise other components.

Generated by OpenCVE AI on October 7, 2026 at 01:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 00:30:00 +0000

Type Values Removed Values Added
First Time appeared Yawkat
Yawkat lz4-java
Vendors & Products Yawkat
Yawkat lz4-java

Tue, 06 Oct 2026 20:00:00 +0000

Type Values Removed Values Added
Description yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.2, LZ4DecompressorWithLength uses getDecompressedLength to trust the four-byte decompressed-length header before validating the compressed input, allowing a five-byte attacker-supplied input whose header declares a large output size to request up to approximately 2 GiB and exhaust the JVM heap. Convenience overloads backed by LZ4FastDecompressor or LZ4SafeDecompressor allocate the untrusted size, while overloads that write to a caller-provided destination buffer are not affected because the caller controls the destination size. This issue is fixed in version 1.11.2.
Title yawkat LZ4 Java: LZ4DecompressorWithLength allocates the unvalidated size from the 4-byte length header, so a 5-byte input triggers a 1 GiB allocation and OutOfMemoryError
Weaknesses CWE-789
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-06T19:54:04.124Z

Reserved: 2026-10-06T16:49:40.591Z

Link: CVE-2026-106453

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T20:17:27.457

Modified: 2026-10-06T20:17:27.457

Link: CVE-2026-106453

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T01:15:09Z

Weaknesses
  • CWE-789

    Memory Allocation with Excessive Size Value