{"id":"CVE-2026-106450","summary":"yawkat LZ4 Java: LZ4FrameInputStream reallocates block buffers for every frame, allowing CPU and GC amplification from small inputs","details":"yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.4, net.jpountz.lz4.LZ4FrameInputStream readHeader() allocates two new 4 MiB block buffers whenever a maximum-block-size frame header is read, and the default concatenated-frame mode allows attacker-controlled streams containing many minimal empty frames to trigger roughly 8 MiB of allocation for every 11 input bytes. The stream produces no decompressed output while consuming CPU and garbage-collection time, so decompressed-size limits do not mitigate the issue; readSingleFrame mode is not affected. This issue is fixed in version 1.11.4.","aliases":["GHSA-gm45-99xc-r7wv"],"modified":"2026-10-07T13:21:00.092539184Z","published":"2026-10-06T19:48:40.092Z","database_specific":{"cwe_ids":["CWE-770"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/106xxx/CVE-2026-106450.json","cna_assigner":"GitHub_M"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/106xxx/CVE-2026-106450.json"},{"type":"FIX","url":"https://github.com/yawkat/lz4-java/commit/2acc0ec1ead226145c62a817c18c8ed49233a283"},{"type":"WEB","url":"https://github.com/yawkat/lz4-java/releases/tag/v1.11.4"},{"type":"ADVISORY","url":"https://github.com/yawkat/lz4-java/security/advisories/GHSA-gm45-99xc-r7wv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106450"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/yawkat/lz4-java","events":[{"introduced":"0"},{"fixed":"4af910bc99c2f021f0cd56f6ca7f7600f4dda4a0"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.11.4"}],"source":"AFFECTED_FIELD"}}],"versions":["v1.11.3","v1.11.2","v1.11.1","v1.11.0","v1.10.4","v1.10.3","v1.10.2","v1.10.1","v1.10.0","v1.9.0","1.8.0","1.7.0","1.6.0","1.5.0","1.4.0","1.3.0","1.2.0","1.0.0"],"database_specific":{"vanir_signatures_modified":"2026-10-07T13:21:00Z","source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-106450.json","vanir_signatures":[{"id":"CVE-2026-106450-51af3d82","signature_type":"Line","signature_version":"v1","source":"https://github.com/yawkat/lz4-java/commit/4af910bc99c2f021f0cd56f6ca7f7600f4dda4a0","target":{"file":"src/test/net/jpountz/lz4/LZ4BlockStreamingTest.java"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["214388248717931299923900274857980516335","65683750676527707633078656054170255344","118287103178809004985414128698616388518","300637533127697537612035724601996989858","266104950906479238541857316988367999351","134728242984367791732063153507024217733","42467283072344628588104348871426341262","120304495577461616964057978192822068584","241948005302004834692069803815921267754","300772486054080233650511326870296722448","199868925319664771762581168079999457280","199852464834928763731943148423675137228","5780372513503982885265799084234661786","185404016909992595827221147264550945351","26652769941461710058292728882523053930","13075325095172813375000686650282311601","269691371974919895669012905319974831748","68119049062416810164251849865742483758","118762952372007463797917670866819281951","269126750384551754583012292750271610628","173611378178514036441531353351102857178"]}},{"id":"CVE-2026-106450-e30894f2","signature_type":"Function","signature_version":"v1","source":"https://github.com/yawkat/lz4-java/commit/4af910bc99c2f021f0cd56f6ca7f7600f4dda4a0","target":{"file":"src/test/net/jpountz/lz4/LZ4BlockStreamingTest.java","function":"testAvailableAfterEmptyBlock"},"deprecated":false,"digest":{"function_hash":"20082239809390668882048052815584052754","length":678}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}]}