CVE-2026-59949

EUVD-2026-60947
yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JNI-backed XXHash implementations fail to validate the byte array object and the off and len arguments in XXHashFactory.nativeInstance().hash32().hash(), XXHashFactory.nativeInstance().hash64().hash(), XXHashFactory.nativeInstance().newStreamingHash32().update(), and XXHashFactory.nativeInstance().newStreamingHash64().update(), allowing null arrays or oversized ranges to reach native code, read outside the Java array, and fatally terminate the JVM. This issue is fixed in version 1.11.1.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
GitHub_MCNA
6.5 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 38.1%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
yawkatlz4_java
𝑥
< 1.11.1
CNA
Debian logo
Debian Releases
Debian Product
Codename
lz4-java
bookworm
postponed
forky
1.11.2+ds1-3
fixed
sid
1.11.2+ds1-3
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
lz4-java
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
needs-triage