PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-106449 yawkat CVE debrief

CVE-2026-106449: The yawkat LZ4 Java library has a vulnerability in LZ4BlockInputStream that causes a StackOverflowError when handling empty blocks with stopOnEmptyBlock=false. This occurs because the refill() method is called recursively for each empty block, leading to a potential denial of service. Defenders should assess exposure and prioritize verification and updates to prevent potential crashes and monitor for exceptions. The vulnerability affects systems handling LZ4 block streams, particularly those using yawkat LZ4 Java.

Vendor
yawkat
Product
at.yawk.lz4:lz4-java
CVSS
LOW 3.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Defenders responsible for systems handling LZ4 block streams, particularly those using yawkat LZ4 Java, should assess exposure and prioritize verification and updates to prevent potential crashes and monitor for exceptions. This includes operators, platform administrators, vulnerability management teams, and security teams who need to review compensating controls for exposed systems while remediation is scheduled and verified.

Why it matters

The CVE-2026-106449 vulnerability in yawkat LZ4 Java can cause StackOverflowError exceptions when handling empty blocks in LZ4BlockInputStream, potentially leading to denial of service and data processing issues. Defenders should prioritize verification and updates to prevent potential crashes and monitor for exceptions.

  • Potential denial of service due to StackOverflowError exceptions
  • Need for verification and updates to prevent potential crashes
  • Possible data processing issues due to recursive refill() calls
  • Importance of monitoring for and responding to StackOverflowError exceptions

Technical summary

The yawkat LZ4 Java library has a vulnerability in LZ4BlockInputStream that causes a StackOverflowError when handling empty blocks with stopOnEmptyBlock=false. This occurs because the refill() method is called recursively for each empty block, leading to a potential denial of service. The vulnerability affects systems handling LZ4 block streams, particularly those using yawkat LZ4 Java. In local testing, around 10,000 to 100,000 consecutive empty blocks threw StackOverflowError. StackOverflowError is an Error, not an IOException, so callers that only handle I/O errors for corrupt input don't catch it.

Defensive priority

Defenders should prioritize verifying and updating affected systems, particularly those handling LZ4 block streams.

Recommended defensive actions

  • Verify and update affected systems, particularly those handling LZ4 block streams
  • Review and test input validation and error handling for LZ4 block streams
  • Monitor for and respond to potential StackOverflowError exceptions
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record and source item provide details on the vulnerability in yawkat LZ4 Java, which causes a StackOverflowError when handling empty blocks in LZ4BlockInputStream. The vulnerability is triggered when LZ4BlockInputStream is configured with stopOnEmptyBlock=false, leading to recursive calls to refill() for each empty block. This can exhaust the thread stack and throw a StackOverflowError out of read() or skip().

Sources and references

Verified primary and authoritative sources

  • CVE-2026-106449 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-106449

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-106449 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-106449

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.