StackRadar

CVE-2026-106449

Low

Advisory

Published 7 Oct 2026In the index since 8 Oct 2026
Severity
Low
worst across findings
CVSS
3.7
base score, highest
EPSS
0.003
25th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
113
of 18,053 indexed, latest versions
Container images
113
deployed by those charts
Fix available
1 of 1
affected package

yawkat LZ4 Java: LZ4BlockInputStream with stopOnEmptyBlock=false recurses once per empty block, causing StackOverflowError

Carried by container images the latest versions of 113 of 18,053 indexed charts deploy, on 113 images.

Affected packageAffected versionsFixed inImages
lz4-javamaven1.10.1, 1.10.2, 1.10.4, 1.11.0+2 more1.11.4113
OSV records
GHSA-343h-94h5-c4wr

Charts affected

113 by stars
ChartLatestAffected imagesRadar Score
pulsarquench-pulsarVerified publisher0.0.221 of 1See more

pulsar quench-pulsar 0.0.22

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/pulsardigest-pinned1b3a533f6607
lz4-java@1.11.1
1.11.4

Open the chart page →

118
skywalkingquench-skywalkingVerified publisher0.0.181 of 1See more

skywalking quench-skywalking 0.0.18

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/skywalkingdigest-pinnedb234844163cf
lz4-java@1.11.2
1.11.4

Open the chart page →

74
streaming-stackquench-streaming-stackVerified publisher0.0.92 of 3See more

streaming-stack quench-streaming-stack 0.0.9

2 of the 3 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/akhqdigest-pinnedf3dddad78840
lz4-java@1.11.1
1.11.4
ghcr.io/quenchworks/images/kafkadigest-pinneda2a8f8c1845b
lz4-java@1.11.1
1.11.4

Open the chart page →

259
trinoquench-trinoVerified publisher0.0.81 of 1See more

trino quench-trino 0.0.8

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/trinodigest-pinnedb88f74961479
lz4-java@1.11.1
1.11.4

Open the chart page →

83
wildflyquench-wildflyVerified publisher0.0.61 of 1See more

wildfly quench-wildfly 0.0.6

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/wildflydigest-pinned51c31ca1bc16
lz4-java@1.11.2
1.11.4

Open the chart page →

72
zipkinquench-zipkinVerified publisher0.0.51 of 1See more

zipkin quench-zipkin 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/zipkindigest-pinnedcd4d4af2076b
lz4-java@1.11.1
1.11.4

Open the chart page →

107
catalog-serverradar-baseVerified publisher0.9.31 of 1See more

catalog-server radar-base 0.9.3

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-schemas/radar-schemas-tools:0.8.16c442e8bfe6b4
lz4-java@1.10.1
1.11.4

Open the chart page →

2,835
radar-gatewayradar-baseVerified publisher1.9.01 of 2See more

radar-gateway radar-base 1.9.0

1 of the 2 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-gateway/radar-gateway:0.9.4219d894aa7a6
lz4-java@1.10.1
1.11.4

Open the chart page →

2,719
hazelcaststakaterVerified publisher1.0.21 of 1See more

hazelcast stakater 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
hazelcast/hazelcast:latestf086bf0ecb23
lz4-java@1.10.1
1.11.4

Open the chart page →

1,932
kafkatwomartensVerified publisher0.2.11 of 2See more

kafka twomartens 0.2.1

1 of the 2 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:latest5e8f3ab5b497
lz4-java@1.11.1
1.11.4

Open the chart page →

1,945
elasticsearchwiremindVerified publisher8.19.11 of 1See more

elasticsearch wiremind 8.19.1

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
library/elasticsearch:8.19.22d071f96fab6c
lz4-java@1.11.1
1.11.4

Open the chart page →

687
metabasewiremindVerified publisher2.27.5-wiremind01 of 1See more

metabase wiremind 2.27.5-wiremind0

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
metabase/metabase:v0.61.1.x9491ed11c901
lz4-java@1.10.4
1.11.4

Open the chart page →

1,878
zipkinzipkinVerified publisher0.5.01 of 1See more

zipkin zipkin 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
openzipkin/zipkin-slim:3.6.0a69e1057df36
lz4-java@1.10.1
1.11.4

Open the chart page →

1,403

Container images carrying it

113 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
folioci/mod-notes:latest998ac4782e0d
lz4-java@1.10.1
1.11.4
1
folioci/mod-oa:latestae3b069d4ba5
lz4-java@1.10.1
1.11.4
1
folioci/mod-orders:latestfc4528220fb8
lz4-java@1.10.1
1.11.4
1
folioci/mod-orders-storage:latestceeaacc3bf16
lz4-java@1.10.1
1.11.4
1
folioci/mod-organizations-storage:lateste46892405fde
lz4-java@1.10.1
1.11.4
1
folioci/mod-patron-blocks:latestde7318069a67
lz4-java@1.10.1
1.11.4
1
folioci/mod-pubsub:latest0a4fa4ad5d72
lz4-java@1.10.1
1.11.4
1
folioci/mod-quick-marc:latest4d70ebda4d00
lz4-java@1.10.1
1.11.4
1
folioci/mod-remote-storage:latest4f12177123dc
lz4-java@1.10.1
1.11.4
1
folioci/mod-search:latest44d7ee9acdf6
lz4-java@1.10.1
1.11.4
1
folioci/mod-serials-management:latest571fa1ffe8c9
lz4-java@1.10.1
1.11.4
1
folioci/mod-service-interaction:latestf53c327a48e8
lz4-java@1.10.1
1.11.4
1
folioci/mod-source-record-manager:latesta940caf026ee
lz4-java@1.10.2
1.11.4
1
folioci/mod-source-record-storage:latesta1434881eeb7
lz4-java@1.10.1
1.11.4
1
folioci/mod-users:latest6f60033321b0
lz4-java@1.10.2
1.11.4
1
graviteeio/am-gateway:4.12.8d09cf41530da
lz4-java@1.10.1
1.11.4
1
graviteeio/am-management-api:4.12.849d0188a58ae
lz4-java@1.10.1
1.11.4
1
graylog/graylog:7.1.9598bd41fefd5
lz4-java@1.10.4
1.11.4
1
graylog/graylog-enterprise:7.1.88a1f641cd7aa
lz4-java@1.10.4
1.11.4
1
hazelcast/hazelcast:latestf086bf0ecb23
lz4-java@1.10.1
1.11.4
1
hazelcast/hazelcast-enterprise:5.7.1cdff425edc10
lz4-java@1.10.1
1.11.4
1
library/cassandra:4.03a4876cc7f18
lz4-java@1.10.1
1.11.4
1
library/elasticsearch:9.5.19656a9ca03f8
lz4-java@1.11.1
1.11.4
1
library/elasticsearch:9.5.3a4e2b3d21ad0
lz4-java@1.11.1
1.11.4
1
library/neo4j:2026.05.0-enterprise2caf944aa4a5
lz4-java@1.11.0
1.11.4
1
metabase/metabase:v0.63.181160b570cb11
lz4-java@1.10.4
1.11.4
1
metabase/metabase:v0.63.1.124f150effd484
lz4-java@1.10.4
1.11.4
1
metabase/metabase:latestb7c6250d7fd2
lz4-java@1.10.4
1.11.4
1
opennms/sentinel:36.0.4e1880996623f
lz4-java@1.10.2
1.11.4
1
opensearchproject/opensearch:2.19.6e321cb03c643
lz4-java@1.10.1
1.11.4
1
openzipkin/zipkin-slim:3.6.0a69e1057df36
lz4-java@1.10.1
1.11.4
1
penpotapp/backend:2.18.32df1b3440d2a
lz4-java@1.11.2
1.11.4
1
strangebee/thehive:5.8.0-1a7f7b05fba24
lz4-java@1.11.2
1.11.4
1
tchiotludo/akhq:0.28.0c2824dc2ae44
lz4-java@1.11.1
1.11.4
1
themoah/klag:0.2.187178531ebe86
lz4-java@1.11.1
1.11.4
1
thingsboard/tbmq-integration-executor:2.4.0b5a9c1addf80
lz4-java@1.11.2
1.11.4
1
thingsboard/tbmq-node:2.4.070661025dba5
lz4-java@1.11.2
1.11.4
1
thingsboard/tb-postgres:latest2d17e4e36edc
lz4-java@1.10.1
1.11.4
1
trinodb/trino:4801565e8cac299
lz4-java@1.10.4
1.11.4
1
trinodb/trino:4815b5e0a97f599
lz4-java@1.11.0
1.11.4
1
ghcr.io/comet-ml/opik/opik-backend:2.2.94809d837a1dcf
lz4-java@1.10.4
1.11.4
1
ghcr.io/eximeebpms/eximeebpms-bpm-platform:run-1.4.00f4a5c0eea07
lz4-java@1.11.2
1.11.4
1
ghcr.io/gla-rad/enav-aton-admin-service:latest8b963221a007
lz4-java@1.10.1
1.11.4
1
ghcr.io/gla-rad/enav-aton-service:latest3ffe10cd9cef
lz4-java@1.10.1
1.11.4
1
ghcr.io/gla-rad/enav-msg-broker:latest5c0966fa0257
lz4-java@1.10.1
1.11.4
1
ghcr.io/kubelauncher/cassandra4a2625365fc6
lz4-java@1.10.1
1.11.4
1
ghcr.io/open-telemetry/demo:3.1.0-kafka4402ba7fd544
lz4-java@1.10.2
1.11.4
1
ghcr.io/open-telemetry/demo:3.1.0-fraud-detectiona07ee694304b
lz4-java@1.10.2
1.11.4
1
ghcr.io/quenchworks/images/elasticsearch6ec7ad24d45c
lz4-java@1.11.1
1.11.4
1
ghcr.io/quenchworks/images/metabase2024b60e8b2f
lz4-java@1.11.1
1.11.4
1

syft 1.42.1 · advisories as of 8 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.