DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-106450: CVE-2026-106450: Denial of Service via Eager Resource Allocation in lz4-java LZ4FrameInputStream

CVE-2026-106450: Denial of Service via Eager Resource Allocation in lz4-java LZ4FrameInputStream

Vulnerability ID: CVE-2026-106450
CVSS Score: 5.3
Published: 2026-10-07

A resource allocation vulnerability (CWE-770) in lz4-java before version 1.11.4 allows an unauthenticated remote attacker to trigger CPU exhaustion and high garbage collection overhead by streaming empty concatenated LZ4 frames.

TL;DR

lz4-java is vulnerable to a CPU and memory allocation Denial of Service. Eager buffer allocation during header parsing allows attackers to stream minimal, 11-byte empty frames that trigger repeated 8 MiB allocations, causing severe JVM Garbage Collection overhead.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-770
  • Attack Vector: Network
  • CVSS v3.1: 5.3 (Medium)
  • EPSS Score: 0.00371 (0.37%)
  • Exploit Status: Proof-of-Concept (PoC)
  • CISA KEV Status: Not Listed

Affected Systems

  • Java applications utilizing lz4-java LZ4FrameInputStream for decompression
  • Web applications exposing endpoints that decompress LZ4 payload data
  • Log parsers, ingestion engines, or streaming pipelines handling LZ4 streams
  • lz4-java: < 1.11.4 (Fixed in: 1.11.4)

Code Analysis

Commit: 2acc0ec

lazily allocate block buffers and reuse them

Commit: f31f44d

fix NullPointerException on skippable-only streams

Exploit Details

  • GitHub: Conceptual discussion and advisory detailing the vulnerability mechanism and reproduction

Mitigation Strategies

  • Upgrade lz4-java to version 1.11.4 or higher
  • Limit incoming network throughput and connection concurrency
  • Implement aggressive timeout thresholds for decompression handlers

Remediation Steps:

  1. Identify and update all references of org.lz4:lz4-java in pom.xml, build.gradle, or other build files.
  2. Upgrade the declared version to 1.11.4 or higher.
  3. Re-compile and run integration tests to verify the update.
  4. Deploy the patched binaries to production environments and monitor garbage collection logs.

References


Read the full report for CVE-2026-106450 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)