CVE-2026-59949

Source
https://cve.org/CVERecord?id=CVE-2026-59949
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-59949.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-59949
Aliases
Downstream
Related
Published
2026-08-18T14:58:08.615Z
Modified
2026-08-19T12:09:54.865286Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H CVSS Calculator
Summary
yawkat LZ4 Java: JVM Crash via Null Byte Array in lz4-java Streaming XXHash JNI (StreamingXXHash32JNI / StreamingXXHash64JNI)
Details

yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JNI-backed XXHash implementations fail to validate the byte array object and the off and len arguments in XXHashFactory.nativeInstance().hash32().hash(), XXHashFactory.nativeInstance().hash64().hash(), XXHashFactory.nativeInstance().newStreamingHash32().update(), and XXHashFactory.nativeInstance().newStreamingHash64().update(), allowing null arrays or oversized ranges to reach native code, read outside the Java array, and fatally terminate the JVM. This issue is fixed in version 1.11.1.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-476"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/59xxx/CVE-2026-59949.json"
}
References

Affected packages

Git / github.com/yawkat/lz4-java

Affected ranges

Type
GIT
Repo
https://github.com/yawkat/lz4-java
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.11.1"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

1.*
1.0.0
1.2.0
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.8.0
v1.*
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.9.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-59949.json"
vanir_signatures
[
    {
        "target": {
            "function": "checkRange",
            "file": "src/java/net/jpountz/util/ByteBufferUtils.java"
        },
        "deprecated": false,
        "source": "https://github.com/yawkat/lz4-java/commit/dbd86d04b8dd716e1c2bc626be54189997d910da",
        "id": "CVE-2026-59949-1129579d",
        "signature_version": "v1",
        "digest": {
            "length": 186.0,
            "function_hash": "87843257706011401096458569905835871820"
        },
        "signature_type": "Function"
    },
    {
        "target": {
            "file": "src/java/net/jpountz/xxhash/StreamingXXHash32JNI.java"
        },
        "deprecated": false,
        "source": "https://github.com/yawkat/lz4-java/commit/dbd86d04b8dd716e1c2bc626be54189997d910da",
        "id": "CVE-2026-59949-2b2f1363",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "52188835542880046349564498428341383900",
                "231544699067850669456960279971253721383",
                "211923169787727576754973573920994276601",
                "248335528281680276630405962134683789745",
                "58135466657490218113187723333196980134"
            ]
        },
        "signature_type": "Line"
    },
    {
        "target": {
            "file": "src/test/net/jpountz/xxhash/XXHash32Test.java"
        },
        "deprecated": false,
        "source": "https://github.com/yawkat/lz4-java/commit/dbd86d04b8dd716e1c2bc626be54189997d910da",
        "id": "CVE-2026-59949-2c669dbb",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "304866370494344815258281362112318671356",
                "48967850846095186398265727146711085655",
                "79078123397949002533772732714079481182"
            ]
        },
        "signature_type": "Line"
    },
    {
        "target": {
            "function": "update",
            "file": "src/java/net/jpountz/xxhash/StreamingXXHash32JNI.java"
        },
        "deprecated": false,
        "source": "https://github.com/yawkat/lz4-java/commit/dbd86d04b8dd716e1c2bc626be54189997d910da",
        "id": "CVE-2026-59949-30fa12ea",
        "signature_version": "v1",
        "digest": {
            "length": 134.0,
            "function_hash": "13203808162700955036236089460995485873"
        },
        "signature_type": "Function"
    },
    {
        "target": {
            "function": "update",
            "file": "src/java/net/jpountz/xxhash/StreamingXXHash64JNI.java"
        },
        "deprecated": false,
        "source": "https://github.com/yawkat/lz4-java/commit/dbd86d04b8dd716e1c2bc626be54189997d910da",
        "id": "CVE-2026-59949-31d7abaa",
        "signature_version": "v1",
        "digest": {
            "length": 134.0,
            "function_hash": "13203808162700955036236089460995485873"
        },
        "signature_type": "Function"
    },
    {
        "target": {
            "file": "src/java/net/jpountz/util/SafeUtils.java"
        },
        "deprecated": false,
        "source": "https://github.com/yawkat/lz4-java/commit/dbd86d04b8dd716e1c2bc626be54189997d910da",
        "id": "CVE-2026-59949-7c63dbd8",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "330721143305649467929160725287579675753",
                "245601943460646559390961719658861209744",
                "212945544987374421026670160724363624371",
                "282959105590060588892199145719928852430",
                "78342574431166125939055639073196142437",
                "23206709006835660294362930811171017006"
            ]
        },
        "signature_type": "Line"
    },
    {
        "target": {
            "file": "src/java/net/jpountz/xxhash/StreamingXXHash64JNI.java"
        },
        "deprecated": false,
        "source": "https://github.com/yawkat/lz4-java/commit/dbd86d04b8dd716e1c2bc626be54189997d910da",
        "id": "CVE-2026-59949-9773ed58",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "284916952506509858234350686753295167330",
                "231544699067850669456960279971253721383",
                "140865726203693627259463320235966644227",
                "204325672512978603042963892560761035410",
                "207300228846805057126989287645128173263"
            ]
        },
        "signature_type": "Line"
    },
    {
        "target": {
            "function": "checkRange",
            "file": "src/java/net/jpountz/util/SafeUtils.java"
        },
        "deprecated": false,
        "source": "https://github.com/yawkat/lz4-java/commit/dbd86d04b8dd716e1c2bc626be54189997d910da",
        "id": "CVE-2026-59949-a386831f",
        "signature_version": "v1",
        "digest": {
            "length": 174.0,
            "function_hash": "26163761408691431529134690922712383932"
        },
        "signature_type": "Function"
    },
    {
        "target": {
            "file": "src/java/net/jpountz/util/ByteBufferUtils.java"
        },
        "deprecated": false,
        "source": "https://github.com/yawkat/lz4-java/commit/dbd86d04b8dd716e1c2bc626be54189997d910da",
        "id": "CVE-2026-59949-d952f45d",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "314517682005774329724241378323916557150",
                "77135545415670281109671568167610075181",
                "307503247210183753018182539938509419254",
                "282959105590060588892199145719928852430",
                "78342574431166125939055639073196142437",
                "203205803628102982033900559480582549669"
            ]
        },
        "signature_type": "Line"
    },
    {
        "target": {
            "file": "src/test/net/jpountz/xxhash/XXHash64Test.java"
        },
        "deprecated": false,
        "source": "https://github.com/yawkat/lz4-java/commit/dbd86d04b8dd716e1c2bc626be54189997d910da",
        "id": "CVE-2026-59949-ea38104c",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "304866370494344815258281362112318671356",
                "48967850846095186398265727146711085655",
                "79078123397949002533772732714079481182"
            ]
        },
        "signature_type": "Line"
    }
]
vanir_signatures_modified
"2026-08-19T12:09:54Z"