StackRadar

CVE-2026-106449

Low

Advisory

Published 7 Oct 2026In the index since 8 Oct 2026
Severity
Low
worst across findings
CVSS
3.7
base score, highest
EPSS
0.003
25th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
113
of 18,053 indexed, latest versions
Container images
113
deployed by those charts
Fix available
1 of 1
affected package

yawkat LZ4 Java: LZ4BlockInputStream with stopOnEmptyBlock=false recurses once per empty block, causing StackOverflowError

Carried by container images the latest versions of 113 of 18,053 indexed charts deploy, on 113 images.

Affected packageAffected versionsFixed inImages
lz4-javamaven1.10.1, 1.10.2, 1.10.4, 1.11.0+2 more1.11.4113
OSV records
GHSA-343h-94h5-c4wr

Charts affected

113 by stars
ChartLatestAffected imagesRadar Score
pulsarquench-pulsarVerified publisher0.0.221 of 1See more

pulsar quench-pulsar 0.0.22

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/pulsardigest-pinned1b3a533f6607
lz4-java@1.11.1
1.11.4

Open the chart page →

118
skywalkingquench-skywalkingVerified publisher0.0.181 of 1See more

skywalking quench-skywalking 0.0.18

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/skywalkingdigest-pinnedb234844163cf
lz4-java@1.11.2
1.11.4

Open the chart page →

74
streaming-stackquench-streaming-stackVerified publisher0.0.92 of 3See more

streaming-stack quench-streaming-stack 0.0.9

2 of the 3 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/akhqdigest-pinnedf3dddad78840
lz4-java@1.11.1
1.11.4
ghcr.io/quenchworks/images/kafkadigest-pinneda2a8f8c1845b
lz4-java@1.11.1
1.11.4

Open the chart page →

259
trinoquench-trinoVerified publisher0.0.81 of 1See more

trino quench-trino 0.0.8

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/trinodigest-pinnedb88f74961479
lz4-java@1.11.1
1.11.4

Open the chart page →

83
wildflyquench-wildflyVerified publisher0.0.61 of 1See more

wildfly quench-wildfly 0.0.6

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/wildflydigest-pinned51c31ca1bc16
lz4-java@1.11.2
1.11.4

Open the chart page →

72
zipkinquench-zipkinVerified publisher0.0.51 of 1See more

zipkin quench-zipkin 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/zipkindigest-pinnedcd4d4af2076b
lz4-java@1.11.1
1.11.4

Open the chart page →

107
catalog-serverradar-baseVerified publisher0.9.31 of 1See more

catalog-server radar-base 0.9.3

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-schemas/radar-schemas-tools:0.8.16c442e8bfe6b4
lz4-java@1.10.1
1.11.4

Open the chart page →

2,835
radar-gatewayradar-baseVerified publisher1.9.01 of 2See more

radar-gateway radar-base 1.9.0

1 of the 2 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-gateway/radar-gateway:0.9.4219d894aa7a6
lz4-java@1.10.1
1.11.4

Open the chart page →

2,719
hazelcaststakaterVerified publisher1.0.21 of 1See more

hazelcast stakater 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
hazelcast/hazelcast:latestf086bf0ecb23
lz4-java@1.10.1
1.11.4

Open the chart page →

1,932
kafkatwomartensVerified publisher0.2.11 of 2See more

kafka twomartens 0.2.1

1 of the 2 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:latest5e8f3ab5b497
lz4-java@1.11.1
1.11.4

Open the chart page →

1,945
elasticsearchwiremindVerified publisher8.19.11 of 1See more

elasticsearch wiremind 8.19.1

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
library/elasticsearch:8.19.22d071f96fab6c
lz4-java@1.11.1
1.11.4

Open the chart page →

687
metabasewiremindVerified publisher2.27.5-wiremind01 of 1See more

metabase wiremind 2.27.5-wiremind0

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
metabase/metabase:v0.61.1.x9491ed11c901
lz4-java@1.10.4
1.11.4

Open the chart page →

1,878
zipkinzipkinVerified publisher0.5.01 of 1See more

zipkin zipkin 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-106449.

Container imageDigestPackageFixed in
openzipkin/zipkin-slim:3.6.0a69e1057df36
lz4-java@1.10.1
1.11.4

Open the chart page →

1,403

Container images carrying it

113 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/quenchworks/images/nifiac51c98e9e37
lz4-java@1.11.2
1.11.4
1
ghcr.io/quenchworks/images/pulsar1b3a533f6607
lz4-java@1.11.1
1.11.4
1
ghcr.io/quenchworks/images/skywalkingb234844163cf
lz4-java@1.11.2
1.11.4
1
ghcr.io/quenchworks/images/wildfly51c31ca1bc16
lz4-java@1.11.2
1.11.4
1
ghcr.io/quenchworks/images/zipkincd4d4af2076b
lz4-java@1.11.1
1.11.4
1
ghcr.io/radar-base/radar-gateway/radar-gateway:0.9.4219d894aa7a6
lz4-java@1.10.1
1.11.4
1
ghcr.io/radar-base/radar-schemas/radar-schemas-tools:0.8.16c442e8bfe6b4
lz4-java@1.10.1
1.11.4
1
public.ecr.aws/aktosecurity/akto-api-security-database-abstractor:1.70.366b0ec8b3de3
lz4-java@1.10.1
1.11.4
1
public.ecr.aws/aktosecurity/akto-api-security-runtime:latestc89a1c10c9c2
lz4-java@1.10.1
1.11.4
1
public.ecr.aws/aktosecurity/akto-threat-detection:1.18.755b1bd20ef02
lz4-java@1.10.1
1.11.4
1
public.ecr.aws/aktosecurity/akto-threat-detection:latestf14d68a2b1cf
lz4-java@1.10.1
1.11.4
1
quay.io/kannika/kannika-api:0.19.05e5a3b3a911e
lz4-java@1.10.2
1.11.4
1
quay.io/strimzi/operator:latest60abcb19699f
lz4-java@1.10.2
1.11.4
1

syft 1.42.1 · advisories as of 8 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.