CVE-2026-106450: yawkat LZ4 Java: LZ4FrameInputStream reallocates block buffers for every frame, allowing CPU and GC amplification from small inputs

Published Oct 6, 2026
·
Updated

yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.4, net.jpountz.lz4.LZ4FrameInputStream readHeader() allocates two new 4 MiB block buffers whenever a maximum-block-size frame header is read, and the default concatenated-frame mode allows attacker-controlled streams containing many minimal empty frames to trigger roughly 8 MiB of allocation for every 11 input bytes. The stream produces no decompressed output while consuming CPU and garbage-collection time, so decompressed-size limits do not mitigate the issue; readSingleFrame mode is not affected. This issue is fixed in version 1.11.4.

Affected Software

1 affected component
yawkat LZ4 Java<1.11.4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade yawkat LZ4 Java to a version that resolves this vulnerability.

    Fixed in 1.11.4

Event History

Oct 6, 2026
CVE Published
via MITRE·07:48 PM
Data Sourced
via MITRE·07:48 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Applications using yawkat LZ4 Java before 1.11.4 that process attacker-controlled LZ4 streams with LZ4FrameInputStream in its default concatenated-frame mode are exposed. Deployments using readSingleFrame mode are not affected.

2

What does an attacker need to exploit it?

An attacker needs to supply a crafted LZ4 input stream containing many minimal empty frames with maximum-block-size headers. No authentication or user interaction is required.

3

Will decompressed-size limits prevent the denial of service?

No. The crafted stream produces no decompressed output, while each small frame can cause roughly 8 MiB of allocation and associated CPU and garbage-collection work.

4

What is the remediation?

Upgrade yawkat LZ4 Java to version 1.11.4. If upgrading is not immediately possible, use readSingleFrame mode rather than the default concatenated-frame mode where applicable.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203