CVE-2026-59949: Yawkat LZ4-Java
Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.
yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JNI-backed XXHash implementations fail to validate the byte array object and the off and len arguments in XXHashFactory.nativeInstance().hash32().hash(), XXHashFactory.nativeInstance().hash64().hash(), XXHashFactory.nativeInstance().newStreamingHash32().update(), and XXHashFactory.nativeInstance().newStreamingHash64().update(), allowing null arrays or oversized ranges to reach native code, read outside the Java array, and fatally terminate the JVM. This issue is fixed in version 1.11.1.
Affected products
- Yawkat LZ4-Java: before 1.11.1 (fixed in 1.11.1)
Published 2026-08-18. Last modified 2026-09-18.