CVE-2026-106453
- EPSS 0.37%
- Veröffentlicht 06.10.2026 19:54:04
- Zuletzt bearbeitet 07.10.2026 17:16:48
yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.2, LZ4DecompressorWithLength uses getDecompressedLength to trust the four-byte decompressed-length header before validating the compressed input, allowing a five-byte attacker-supplied ...
CVE-2026-106452
- EPSS 0.37%
- Veröffentlicht 06.10.2026 19:52:37
- Zuletzt bearbeitet 07.10.2026 13:58:29
yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.2, net.jpountz.lz4.LZ4BlockInputStream refill() validates that the compressedLen field in a legacy LZ4Block header is nonnegative but allocates a compressed-input buffer of that attacke...
CVE-2026-106451
- EPSS 0.08%
- Veröffentlicht 06.10.2026 19:50:41
- Zuletzt bearbeitet 07.10.2026 19:17:32
yawkat LZ4 Java provides LZ4 compression for Java. From 1.7.0 until 1.11.4, net.jpountz.util.Native.load() uses File.createTempFile to create an exclusive temporary .lck file but derives the native-library path by removing the suffix, then FileOutput...
CVE-2026-106450
- EPSS 0.37%
- Veröffentlicht 06.10.2026 19:48:40
- Zuletzt bearbeitet 07.10.2026 13:58:29
yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.4, net.jpountz.lz4.LZ4FrameInputStream readHeader() allocates two new 4 MiB block buffers whenever a maximum-block-size frame header is read, and the default concatenated-frame mode all...
CVE-2026-106449
- EPSS 0.34%
- Veröffentlicht 06.10.2026 19:46:28
- Zuletzt bearbeitet 07.10.2026 17:16:47
yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.4, net.jpountz.lz4.LZ4BlockInputStream configured with stopOnEmptyBlock set to false handles each well-formed empty LZ4Block by recursively calling refill(), allowing a long sequence of...
CVE-2026-59949
- EPSS 0.46%
- Veröffentlicht 18.08.2026 14:58:08
- Zuletzt bearbeitet 18.09.2026 20:09:01
yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JNI-backed XXHash implementations fail to validate the byte array object and the off and len arguments in XXHashFactory.nativeInstance().hash32().hash(), XXHashFactory.nativeInstance...