Uncontrolled Recursion in lz4-java - #VU153028
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled recursion in net.jpountz.lz4.LZ4BlockInputStream.refill() when processing consecutive empty blocks in LZ4Block streams with stopOnEmptyBlock set to false. A remote attacker can supply a stream containing a long run of empty blocks to cause a denial of service.
The default stopOnEmptyBlock=true configuration is not affected.