DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-106449: CVE-2026-106449: Stack Overflow via Uncontrolled Recursion in yawkat lz4-java

CVE-2026-106449: Stack Overflow via Uncontrolled Recursion in yawkat lz4-java

Vulnerability ID: CVE-2026-106449
CVSS Score: 3.7
Published: 2026-10-07

A Denial of Service (DoS) vulnerability exists in the yawkat fork of lz4-java prior to version 1.11.4. Under specific non-default configurations (stopOnEmptyBlock = false), parsing crafted streams with a large sequence of contiguous empty LZ4 blocks triggers uncontrolled recursion inside the LZ4BlockInputStream.refill() method, causing stack exhaustion and thread termination.

TL;DR

An uncontrolled recursion vulnerability in lz4-java allows remote attackers to trigger a stack overflow and thread termination by supplying compressed streams with repeated empty blocks when stopOnEmptyBlock is disabled.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-674 (Uncontrolled Recursion)
  • Attack Vector: Network (AV:N)
  • Attack Complexity: High (AC:H)
  • CVSS Score: 3.7 (Low)
  • EPSS Score: 0.00339 (Percentile: 25.20%)
  • Impact Status: Denial of Service (Thread Death)
  • Exploit Status: Proof of Concept Available
  • KEV Status: Not Listed

Affected Systems

  • Java applications using yawkat lz4-java prior to v1.11.4 with stopOnEmptyBlock set to false
  • lz4-java: < 1.11.4 (Fixed in: 1.11.4)

Code Analysis

Commit: c8ebf97

Convert recursive refill implementation to an iterative loop to avoid StackOverflowError when reading many empty blocks

Exploit Details

  • GitHub: Reproduction unit test added directly to the official project codebase repository under net.jpountz.lz4.LZ4BlockStreamingTest

Mitigation Strategies

  • Upgrade the lz4-java library to version 1.11.4 or higher.
  • Enforce stopOnEmptyBlock to true during the instantiation of LZ4BlockInputStream.
  • Implement deep validation of raw compressed payloads at edge gateways to identify and drop repeating structural blocks.

Remediation Steps:

  1. Locate Maven pom.xml or Gradle build.gradle files containing 'org.lz4:lz4-java'.
  2. Update the version identifier coordinate to '1.11.4'.
  3. Scan application code for manual instantiations of net.jpountz.lz4.LZ4BlockInputStream.
  4. Ensure that any initialization of LZ4BlockInputStream passing stopOnEmptyBlock as false is safely removed or refactored.
  5. Recompile, run integration suites, and deploy the patched package to production.

References


Read the full report for CVE-2026-106449 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)