CYBER CODE RED

Get real-time updates on Telegram

Verified

CVE-2026-106451: lz4-java < 1.11.4

Affected technology

lz4-java · < 1.11.4
yawkat

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 4.0): Local · Low privileges required · No user interaction required

What an attacker can do

Another local user with access to the same shared temporary directory can create or replace the library file before System.load() uses it. Vendor/CNA’s CVSS 4.0 assessment (base score 7.3/10) rates confidentiality, integrity and availability impact as high.

Published

CWE
CWE-367, CWE-377
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-106451.html