CVE-2026-106449 | yawkat lz4-java up to 1.11.3 LZ4BlockInputStream refill stopOnEmptyBlock stack-based overflow
A vulnerability was found in yawkat lz4-java up to 1.11.3 and classified as problematic. The affected element is the function refill of the component LZ4BlockInputStream. Such manipulation of the argument stopOnEmptyBlock leads to stack-based buffer overflow.
This vulnerability is referenced as CVE-2026-106449. It is possible to launch the attack remotely. No exploit is available.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More