CVE-2026-106449: Stack Overflow via Uncontrolled Recursion in yawkat lz4-java
Vulnerability ID: CVE-2026-106449
CVSS Score: 3.7
Published: 2026-10-07
A Denial of Service (DoS) vulnerability exists in the yawkat fork of lz4-java prior to version 1.11.4. Under specific non-default configurations (stopOnEmptyBlock = false), parsing crafted streams with a large sequence of contiguous empty LZ4 blocks triggers uncontrolled recursion inside the LZ4BlockInputStream.refill() method, causing stack exhaustion and thread termination.
TL;DR
An uncontrolled recursion vulnerability in lz4-java allows remote attackers to trigger a stack overflow and thread termination by supplying compressed streams with repeated empty blocks when stopOnEmptyBlock is disabled.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-674 (Uncontrolled Recursion)
- Attack Vector: Network (AV:N)
- Attack Complexity: High (AC:H)
- CVSS Score: 3.7 (Low)
- EPSS Score: 0.00339 (Percentile: 25.20%)
- Impact Status: Denial of Service (Thread Death)
- Exploit Status: Proof of Concept Available
- KEV Status: Not Listed
Affected Systems
- Java applications using yawkat lz4-java prior to v1.11.4 with stopOnEmptyBlock set to false
-
lz4-java: < 1.11.4 (Fixed in:
1.11.4)
Code Analysis
Commit: c8ebf97
Convert recursive refill implementation to an iterative loop to avoid StackOverflowError when reading many empty blocks
Exploit Details
- GitHub: Reproduction unit test added directly to the official project codebase repository under net.jpountz.lz4.LZ4BlockStreamingTest
Mitigation Strategies
- Upgrade the lz4-java library to version 1.11.4 or higher.
- Enforce stopOnEmptyBlock to true during the instantiation of LZ4BlockInputStream.
- Implement deep validation of raw compressed payloads at edge gateways to identify and drop repeating structural blocks.
Remediation Steps:
- Locate Maven pom.xml or Gradle build.gradle files containing 'org.lz4:lz4-java'.
- Update the version identifier coordinate to '1.11.4'.
- Scan application code for manual instantiations of net.jpountz.lz4.LZ4BlockInputStream.
- Ensure that any initialization of LZ4BlockInputStream passing stopOnEmptyBlock as false is safely removed or refactored.
- Recompile, run integration suites, and deploy the patched package to production.
References
- Fix Commit
- Release v1.11.4
- GitHub Security Advisory
- NVD Vulnerability Details
- CVE.org Record
- CVE Project Raw JSON Metadata File
- Wiz Vulnerability Database Details
Read the full report for CVE-2026-106449 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)