StackRadar

CVE-2026-106449

Low

Advisory

Published 7 Oct 2026In the index since 8 Oct 2026
Severity
Low
worst across findings
CVSS
3.7
base score, highest
EPSS
0.003
25th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
113
of 18,053 indexed, latest versions
Container images
113
deployed by those charts
Fix available
1 of 1
affected package

yawkat LZ4 Java: LZ4BlockInputStream with stopOnEmptyBlock=false recurses once per empty block, causing StackOverflowError

Carried by container images the latest versions of 113 of 18,053 indexed charts deploy, on 113 images.

Affected packageAffected versionsFixed inImages
lz4-javamaven1.10.1, 1.10.2, 1.10.4, 1.11.0+2 more1.11.4113
OSV records
GHSA-343h-94h5-c4wr

Charts affected

113 by stars
ChartLatestAffected imagesRadar Score
eximeebpmseximeebpms-k8sOfficialVerified publisher0.4.11 of 1See more

eximeebpms eximeebpms-k8s 0.4.1

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
ghcr.io/eximeebpms/eximeebpms-bpm-platform:run-1.4.00f4a5c0eea07
lz4-java@1.11.2
1.11.4

Open the chart page →

287
factor-platformfactorhouseVerified publisher0.0.51 of 1See more

factor-platform factorhouse 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
factorhouse/factor-platform:96.5b19f8edcb778
lz4-java@1.11.1
1.11.4

Open the chart page →

139
mod-agreementsfolio-org0.1.321 of 1See more

mod-agreements folio-org 0.1.32

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
folioci/mod-agreements:latest29c3f233a498
lz4-java@1.10.1
1.11.4

Open the chart page →

1,902
mod-auditfolio-org0.1.361 of 1See more

mod-audit folio-org 0.1.36

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
folioci/mod-audit:latest88f40730ed45
lz4-java@1.10.1
1.11.4

Open the chart page →

267
mod-circulationfolio-org0.1.351 of 1See more

mod-circulation folio-org 0.1.35

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
folioci/mod-circulation:latest3eecd2ac2d8a
lz4-java@1.10.1
1.11.4

Open the chart page →

500
mod-circulation-storagefolio-org0.1.351 of 1See more

mod-circulation-storage folio-org 0.1.35

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
folioci/mod-circulation-storage:latest6bdddcafbc0f
lz4-java@1.10.1
1.11.4

Open the chart page →

662
mod-data-export-springfolio-org0.1.41 of 1See more

mod-data-export-spring folio-org 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
folioci/mod-data-export-spring:latestf1d7caf4544b
lz4-java@1.10.1
1.11.4

Open the chart page →

1,258
mod-data-export-workerfolio-org0.1.151 of 1See more

mod-data-export-worker folio-org 0.1.15

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
folioci/mod-data-export-worker:latest1ad1811c9b37
lz4-java@1.10.1
1.11.4

Open the chart page →

1,244
mod-data-importfolio-org0.1.381 of 1See more

mod-data-import folio-org 0.1.38

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
folioci/mod-data-import:latestec2c3ebe3f2b
lz4-java@1.10.2
1.11.4

Open the chart page →

11
mod-entities-linksfolio-org0.1.11 of 1See more

mod-entities-links folio-org 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
folioci/mod-entities-links:latest3e2412815c0f
lz4-java@1.10.1
1.11.4

Open the chart page →

312
mod-inn-reachfolio-org0.1.71 of 1See more

mod-inn-reach folio-org 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
folioci/mod-inn-reach:latestcc8584e43382
lz4-java@1.10.1
1.11.4

Open the chart page →

513
mod-inventoryfolio-org0.1.361 of 1See more

mod-inventory folio-org 0.1.36

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
folioci/mod-inventory:latest53518ba29668
lz4-java@1.10.2
1.11.4

Open the chart page →

33
mod-inventory-storagefolio-org0.1.371 of 1See more

mod-inventory-storage folio-org 0.1.37

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
folioci/mod-inventory-storage:latestf92ff0a3ca40
lz4-java@1.10.1
1.11.4

Open the chart page →

81
mod-invoicefolio-org0.1.351 of 1See more

mod-invoice folio-org 0.1.35

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
folioci/mod-invoice:latest45b7b13e81e1
lz4-java@1.10.1
1.11.4

Open the chart page →

571
mod-invoice-storagefolio-org0.1.341 of 1See more

mod-invoice-storage folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
folioci/mod-invoice-storage:latest0bc720abcb78
lz4-java@1.10.1
1.11.4

Open the chart page →

226
mod-licensesfolio-org0.1.321 of 1See more

mod-licenses folio-org 0.1.32

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
folioci/mod-licenses:latestcfd6109bf477
lz4-java@1.10.1
1.11.4

Open the chart page →

1,787
mod-notesfolio-org0.1.341 of 1See more

mod-notes folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
folioci/mod-notes:latest998ac4782e0d
lz4-java@1.10.1
1.11.4

Open the chart page →

157
mod-oafolio-org0.1.21 of 1See more

mod-oa folio-org 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
folioci/mod-oa:latestae3b069d4ba5
lz4-java@1.10.1
1.11.4

Open the chart page →

1,735
mod-ordersfolio-org0.1.341 of 1See more

mod-orders folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
folioci/mod-orders:latestfc4528220fb8
lz4-java@1.10.1
1.11.4

Open the chart page →

458
mod-orders-storagefolio-org0.1.351 of 1See more

mod-orders-storage folio-org 0.1.35

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
folioci/mod-orders-storage:latestceeaacc3bf16
lz4-java@1.10.1
1.11.4

Open the chart page →

443
mod-organizations-storagefolio-org0.1.341 of 1See more

mod-organizations-storage folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
folioci/mod-organizations-storage:lateste46892405fde
lz4-java@1.10.1
1.11.4

Open the chart page →

670
mod-patron-blocksfolio-org0.1.341 of 1See more

mod-patron-blocks folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
folioci/mod-patron-blocks:latestde7318069a67
lz4-java@1.10.1
1.11.4

Open the chart page →

360
mod-pubsubfolio-org0.1.341 of 1See more

mod-pubsub folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
folioci/mod-pubsub:latest0a4fa4ad5d72
lz4-java@1.10.1
1.11.4

Open the chart page →

1,017
mod-quick-marcfolio-org0.1.351 of 1See more

mod-quick-marc folio-org 0.1.35

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
folioci/mod-quick-marc:latest4d70ebda4d00
lz4-java@1.10.1
1.11.4

Open the chart page →

63
mod-remote-storagefolio-org0.1.321 of 1See more

mod-remote-storage folio-org 0.1.32

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
folioci/mod-remote-storage:latest4f12177123dc
lz4-java@1.10.1
1.11.4

Open the chart page →

572
mod-searchfolio-org0.1.351 of 1See more

mod-search folio-org 0.1.35

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
folioci/mod-search:latest44d7ee9acdf6
lz4-java@1.10.1
1.11.4

Open the chart page →

1,561
mod-serials-managementfolio-org0.1.11 of 1See more

mod-serials-management folio-org 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
folioci/mod-serials-management:latest571fa1ffe8c9
lz4-java@1.10.1
1.11.4

Open the chart page →

1,735
mod-service-interactionfolio-org0.1.61 of 1See more

mod-service-interaction folio-org 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
folioci/mod-service-interaction:latestf53c327a48e8
lz4-java@1.10.1
1.11.4

Open the chart page →

1,735
mod-source-record-managerfolio-org0.1.371 of 1See more

mod-source-record-manager folio-org 0.1.37

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
folioci/mod-source-record-manager:latesta940caf026ee
lz4-java@1.10.2
1.11.4

Open the chart page →

59
mod-source-record-storagefolio-org0.1.371 of 1See more

mod-source-record-storage folio-org 0.1.37

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
folioci/mod-source-record-storage:latesta1434881eeb7
lz4-java@1.10.1
1.11.4

Open the chart page →

11
mod-usersfolio-org0.1.341 of 1See more

mod-users folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
folioci/mod-users:latest6f60033321b0
lz4-java@1.10.2
1.11.4

Open the chart page →

432
druidhelmforgeVerified publisher1.3.61 of 4See more

druid helmforge 1.3.6

1 of the 4 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
apache/druid:37.0.00116fb802786
lz4-java@1.10.2
1.11.4

Open the chart page →

9,667
elasticsearchhelmforgeVerified publisher1.1.81 of 2See more

elasticsearch helmforge 1.1.8

1 of the 2 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
library/elasticsearch:9.5.3a4e2b3d21ad0
lz4-java@1.11.1
1.11.4

Open the chart page →

484
kibanahelmforgeVerified publisher1.1.81 of 3See more

kibana helmforge 1.1.8

1 of the 3 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
library/elasticsearch:9.5.19656a9ca03f8
lz4-java@1.11.1
1.11.4

Open the chart page →

602
metabasehelmforgeVerified publisher1.2.301 of 3See more

metabase helmforge 1.2.30

1 of the 3 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
metabase/metabase:v0.63.181160b570cb11
lz4-java@1.10.4
1.11.4

Open the chart page →

1,842
ibm-events-operatoribm-helm6.0.0+20260126.110734.01 of 1See more

ibm-events-operator ibm-helm 6.0.0+20260126.110734.0

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:latest60abcb19699f
lz4-java@1.10.2
1.11.4

Open the chart page →

99
thehiveittrident-oss0.1.01 of 6See more

thehive ittrident-oss 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
library/cassandra:4.03a4876cc7f18
lz4-java@1.10.1
1.11.4

Open the chart page →

7,173
kannikakannika0.19.01 of 3See more

kannika kannika 0.19.0

1 of the 3 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
quay.io/kannika/kannika-api:0.19.05e5a3b3a911e
lz4-java@1.10.2
1.11.4

Open the chart page →

1,037
klagklagVerified publisher0.3.171 of 1See more

klag klag 0.3.17

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
themoah/klag:0.2.187178531ebe86
lz4-java@1.11.1
1.11.4

Open the chart page →

646
sentinelopennms-helm-chartsVerified publisher0.5.01 of 2See more

sentinel opennms-helm-charts 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
opennms/sentinel:36.0.4e1880996623f
lz4-java@1.10.2
1.11.4

Open the chart page →

2,175
cp-cmfopenshift2.4.31 of 1See more

cp-cmf openshift 2.4.3

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
confluentinc/cp-cmf:2.4.3c7617bf49a1b
lz4-java@1.11.1
1.11.4

Open the chart page →

98
trinoopstty0.2.141 of 1See more

trino opstty 0.2.14

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
trinodb/trino:4815b5e0a97f599
lz4-java@1.11.0
1.11.4

Open the chart page →

1,510
akhqquench-akhqVerified publisher0.0.51 of 1See more

akhq quench-akhq 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/akhqdigest-pinnedf3dddad78840
lz4-java@1.11.1
1.11.4

Open the chart page →

83
cadencequench-cadenceVerified publisher0.0.221 of 2See more

cadence quench-cadence 0.0.22

1 of the 2 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/cassandradigest-pinned2828b88f226a
lz4-java@1.11.1
1.11.4

Open the chart page →

99
cassandraquench-cassandraVerified publisher0.0.241 of 1See more

cassandra quench-cassandra 0.0.24

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/cassandradigest-pinned2828b88f226a
lz4-java@1.11.1
1.11.4

Open the chart page →

83
elasticsearchquench-elasticsearchVerified publisher0.0.231 of 1See more

elasticsearch quench-elasticsearch 0.0.23

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/elasticsearchdigest-pinned6ec7ad24d45c
lz4-java@1.11.1
1.11.4

Open the chart page →

83
kafkaquench-kafkaVerified publisher0.0.221 of 1See more

kafka quench-kafka 0.0.22

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/kafkadigest-pinneda2a8f8c1845b
lz4-java@1.11.1
1.11.4

Open the chart page →

83
lakehouse-stackquench-lakehouse-stackVerified publisher0.0.121 of 4See more

lakehouse-stack quench-lakehouse-stack 0.0.12

1 of the 4 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/trinodigest-pinnedb88f74961479
lz4-java@1.11.1
1.11.4

Open the chart page →

179
metabasequench-metabase0.0.61 of 2See more

metabase quench-metabase 0.0.6

1 of the 2 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/metabasedigest-pinned2024b60e8b2f
lz4-java@1.11.1
1.11.4

Open the chart page →

152
nifiquench-nifiVerified publisher0.0.51 of 1See more

nifi quench-nifi 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/nifidigest-pinnedac51c98e9e37
lz4-java@1.11.2
1.11.4

Open the chart page →

135

Container images carrying it

113 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
folioci/mod-notes:latest998ac4782e0d
lz4-java@1.10.1
1.11.4
1
folioci/mod-oa:latestae3b069d4ba5
lz4-java@1.10.1
1.11.4
1
folioci/mod-orders:latestfc4528220fb8
lz4-java@1.10.1
1.11.4
1
folioci/mod-orders-storage:latestceeaacc3bf16
lz4-java@1.10.1
1.11.4
1
folioci/mod-organizations-storage:lateste46892405fde
lz4-java@1.10.1
1.11.4
1
folioci/mod-patron-blocks:latestde7318069a67
lz4-java@1.10.1
1.11.4
1
folioci/mod-pubsub:latest0a4fa4ad5d72
lz4-java@1.10.1
1.11.4
1
folioci/mod-quick-marc:latest4d70ebda4d00
lz4-java@1.10.1
1.11.4
1
folioci/mod-remote-storage:latest4f12177123dc
lz4-java@1.10.1
1.11.4
1
folioci/mod-search:latest44d7ee9acdf6
lz4-java@1.10.1
1.11.4
1
folioci/mod-serials-management:latest571fa1ffe8c9
lz4-java@1.10.1
1.11.4
1
folioci/mod-service-interaction:latestf53c327a48e8
lz4-java@1.10.1
1.11.4
1
folioci/mod-source-record-manager:latesta940caf026ee
lz4-java@1.10.2
1.11.4
1
folioci/mod-source-record-storage:latesta1434881eeb7
lz4-java@1.10.1
1.11.4
1
folioci/mod-users:latest6f60033321b0
lz4-java@1.10.2
1.11.4
1
graviteeio/am-gateway:4.12.8d09cf41530da
lz4-java@1.10.1
1.11.4
1
graviteeio/am-management-api:4.12.849d0188a58ae
lz4-java@1.10.1
1.11.4
1
graylog/graylog:7.1.9598bd41fefd5
lz4-java@1.10.4
1.11.4
1
graylog/graylog-enterprise:7.1.88a1f641cd7aa
lz4-java@1.10.4
1.11.4
1
hazelcast/hazelcast:latestf086bf0ecb23
lz4-java@1.10.1
1.11.4
1
hazelcast/hazelcast-enterprise:5.7.1cdff425edc10
lz4-java@1.10.1
1.11.4
1
library/cassandra:4.03a4876cc7f18
lz4-java@1.10.1
1.11.4
1
library/elasticsearch:9.5.19656a9ca03f8
lz4-java@1.11.1
1.11.4
1
library/elasticsearch:9.5.3a4e2b3d21ad0
lz4-java@1.11.1
1.11.4
1
library/neo4j:2026.05.0-enterprise2caf944aa4a5
lz4-java@1.11.0
1.11.4
1
metabase/metabase:v0.63.181160b570cb11
lz4-java@1.10.4
1.11.4
1
metabase/metabase:v0.63.1.124f150effd484
lz4-java@1.10.4
1.11.4
1
metabase/metabase:latestb7c6250d7fd2
lz4-java@1.10.4
1.11.4
1
opennms/sentinel:36.0.4e1880996623f
lz4-java@1.10.2
1.11.4
1
opensearchproject/opensearch:2.19.6e321cb03c643
lz4-java@1.10.1
1.11.4
1
openzipkin/zipkin-slim:3.6.0a69e1057df36
lz4-java@1.10.1
1.11.4
1
penpotapp/backend:2.18.32df1b3440d2a
lz4-java@1.11.2
1.11.4
1
strangebee/thehive:5.8.0-1a7f7b05fba24
lz4-java@1.11.2
1.11.4
1
tchiotludo/akhq:0.28.0c2824dc2ae44
lz4-java@1.11.1
1.11.4
1
themoah/klag:0.2.187178531ebe86
lz4-java@1.11.1
1.11.4
1
thingsboard/tbmq-integration-executor:2.4.0b5a9c1addf80
lz4-java@1.11.2
1.11.4
1
thingsboard/tbmq-node:2.4.070661025dba5
lz4-java@1.11.2
1.11.4
1
thingsboard/tb-postgres:latest2d17e4e36edc
lz4-java@1.10.1
1.11.4
1
trinodb/trino:4801565e8cac299
lz4-java@1.10.4
1.11.4
1
trinodb/trino:4815b5e0a97f599
lz4-java@1.11.0
1.11.4
1
ghcr.io/comet-ml/opik/opik-backend:2.2.94809d837a1dcf
lz4-java@1.10.4
1.11.4
1
ghcr.io/eximeebpms/eximeebpms-bpm-platform:run-1.4.00f4a5c0eea07
lz4-java@1.11.2
1.11.4
1
ghcr.io/gla-rad/enav-aton-admin-service:latest8b963221a007
lz4-java@1.10.1
1.11.4
1
ghcr.io/gla-rad/enav-aton-service:latest3ffe10cd9cef
lz4-java@1.10.1
1.11.4
1
ghcr.io/gla-rad/enav-msg-broker:latest5c0966fa0257
lz4-java@1.10.1
1.11.4
1
ghcr.io/kubelauncher/cassandra4a2625365fc6
lz4-java@1.10.1
1.11.4
1
ghcr.io/open-telemetry/demo:3.1.0-kafka4402ba7fd544
lz4-java@1.10.2
1.11.4
1
ghcr.io/open-telemetry/demo:3.1.0-fraud-detectiona07ee694304b
lz4-java@1.10.2
1.11.4
1
ghcr.io/quenchworks/images/elasticsearch6ec7ad24d45c
lz4-java@1.11.1
1.11.4
1
ghcr.io/quenchworks/images/metabase2024b60e8b2f
lz4-java@1.11.1
1.11.4
1

syft 1.42.1 · advisories as of 8 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.