CVE-2026-106450: Denial of Service via Eager Resource Allocation in lz4-java LZ4FrameInputStream
Vulnerability ID: CVE-2026-106450
CVSS Score: 5.3
Published: 2026-10-07
A resource allocation vulnerability (CWE-770) in lz4-java before version 1.11.4 allows an unauthenticated remote attacker to trigger CPU exhaustion and high garbage collection overhead by streaming empty concatenated LZ4 frames.
TL;DR
lz4-java is vulnerable to a CPU and memory allocation Denial of Service. Eager buffer allocation during header parsing allows attackers to stream minimal, 11-byte empty frames that trigger repeated 8 MiB allocations, causing severe JVM Garbage Collection overhead.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-770
- Attack Vector: Network
- CVSS v3.1: 5.3 (Medium)
- EPSS Score: 0.00371 (0.37%)
- Exploit Status: Proof-of-Concept (PoC)
- CISA KEV Status: Not Listed
Affected Systems
- Java applications utilizing lz4-java LZ4FrameInputStream for decompression
- Web applications exposing endpoints that decompress LZ4 payload data
- Log parsers, ingestion engines, or streaming pipelines handling LZ4 streams
-
lz4-java: < 1.11.4 (Fixed in:
1.11.4)
Code Analysis
Commit: 2acc0ec
lazily allocate block buffers and reuse them
Commit: f31f44d
fix NullPointerException on skippable-only streams
Exploit Details
- GitHub: Conceptual discussion and advisory detailing the vulnerability mechanism and reproduction
Mitigation Strategies
- Upgrade lz4-java to version 1.11.4 or higher
- Limit incoming network throughput and connection concurrency
- Implement aggressive timeout thresholds for decompression handlers
Remediation Steps:
- Identify and update all references of org.lz4:lz4-java in pom.xml, build.gradle, or other build files.
- Upgrade the declared version to 1.11.4 or higher.
- Re-compile and run integration tests to verify the update.
- Deploy the patched binaries to production environments and monitor garbage collection logs.
References
Read the full report for CVE-2026-106450 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)