CVE-2026-59949 | yawkat lz4-java up to 1.11.0 JNI-backed XXHash Implementation off/len out-of-bounds
A vulnerability was found in yawkat lz4-java up to 1.11.0 and classified as critical. This vulnerability affects the function XXHashFactory.nativeInstance.hash32.hash/XXHashFactory.nativeInstance.hash64.hash/XXHashFactory.nativeInstance.newStreamingHash32.update/XXHashFactory.nativeInstance.newStreamingHash64.update of the component JNI-backed XXHash Implementation. Such manipulation of the argument off/len leads to out-of-bounds read.
This vulnerability is traded as CVE-2026-59949. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More