Vulnerability Description
yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JNI-backed XXHash implementations fail to validate the byte array object and the off and len arguments in XXHashFactory.nativeInstance().hash32().hash(), XXHashFactory.nativeInstance().hash64().hash(), XXHashFactory.nativeInstance().newStreamingHash32().update(), and XXHashFactory.nativeInstance().newStreamingHash64().update(), allowing null arrays or oversized ranges to reach native code, read outside the Java array, and fatally terminate the JVM. This issue is fixed in version 1.11.1.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/yawkat/lz4-java/commit/dbd86d04b8dd716e1c2bc626be54189997d910
- https://github.com/yawkat/lz4-java/releases/tag/v1.11.1
- https://github.com/yawkat/lz4-java/security/advisories/GHSA-xx22-p4ch-683r
FAQ
What is CVE-2026-59949?
CVE-2026-59949 is a vulnerability with a CVSS score of 6.5 (MEDIUM). yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JNI-backed XXHash implementations fail to validate the byte array object and the off and len arguments in XXHashFactory.nativeInstan...
How severe is CVE-2026-59949?
CVE-2026-59949 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-59949?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.