StackRadar

CVE-2026-106450

Medium

Advisory

Published 7 Oct 2026In the index since 8 Oct 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
29th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
113
of 18,053 indexed, latest versions
Container images
113
deployed by those charts
Fix available
1 of 1
affected package

yawkat LZ4 Java: LZ4FrameInputStream reallocates block buffers for every frame, allowing CPU and GC amplification from small inputs

Carried by container images the latest versions of 113 of 18,053 indexed charts deploy, on 113 images.

Affected packageAffected versionsFixed inImages
lz4-javamaven1.10.1, 1.10.2, 1.10.4, 1.11.0+2 more1.11.4113
OSV records
GHSA-gm45-99xc-r7wv

Charts affected

113 by stars
ChartLatestAffected imagesRadar Score
pulsarquench-pulsarVerified publisher0.0.221 of 1See more

pulsar quench-pulsar 0.0.22

1 of the 1 container images this version deploys carry CVE-2026-106450.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/pulsardigest-pinned1b3a533f6607
lz4-java@1.11.1
1.11.4

Open the chart page →

118
skywalkingquench-skywalkingVerified publisher0.0.181 of 1See more

skywalking quench-skywalking 0.0.18

1 of the 1 container images this version deploys carry CVE-2026-106450.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/skywalkingdigest-pinnedb234844163cf
lz4-java@1.11.2
1.11.4

Open the chart page →

74
streaming-stackquench-streaming-stackVerified publisher0.0.92 of 3See more

streaming-stack quench-streaming-stack 0.0.9

2 of the 3 container images this version deploys carry CVE-2026-106450.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/akhqdigest-pinnedf3dddad78840
lz4-java@1.11.1
1.11.4
ghcr.io/quenchworks/images/kafkadigest-pinneda2a8f8c1845b
lz4-java@1.11.1
1.11.4

Open the chart page →

259
trinoquench-trinoVerified publisher0.0.81 of 1See more

trino quench-trino 0.0.8

1 of the 1 container images this version deploys carry CVE-2026-106450.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/trinodigest-pinnedb88f74961479
lz4-java@1.11.1
1.11.4

Open the chart page →

83
wildflyquench-wildflyVerified publisher0.0.61 of 1See more

wildfly quench-wildfly 0.0.6

1 of the 1 container images this version deploys carry CVE-2026-106450.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/wildflydigest-pinned51c31ca1bc16
lz4-java@1.11.2
1.11.4

Open the chart page →

72
zipkinquench-zipkinVerified publisher0.0.51 of 1See more

zipkin quench-zipkin 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-106450.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/zipkindigest-pinnedcd4d4af2076b
lz4-java@1.11.1
1.11.4

Open the chart page →

107
catalog-serverradar-baseVerified publisher0.9.31 of 1See more

catalog-server radar-base 0.9.3

1 of the 1 container images this version deploys carry CVE-2026-106450.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-schemas/radar-schemas-tools:0.8.16c442e8bfe6b4
lz4-java@1.10.1
1.11.4

Open the chart page →

2,835
radar-gatewayradar-baseVerified publisher1.9.01 of 2See more

radar-gateway radar-base 1.9.0

1 of the 2 container images this version deploys carry CVE-2026-106450.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-gateway/radar-gateway:0.9.4219d894aa7a6
lz4-java@1.10.1
1.11.4

Open the chart page →

2,719
hazelcaststakaterVerified publisher1.0.21 of 1See more

hazelcast stakater 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-106450.

Container imageDigestPackageFixed in
hazelcast/hazelcast:latestf086bf0ecb23
lz4-java@1.10.1
1.11.4

Open the chart page →

1,932
kafkatwomartensVerified publisher0.2.11 of 2See more

kafka twomartens 0.2.1

1 of the 2 container images this version deploys carry CVE-2026-106450.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:latest5e8f3ab5b497
lz4-java@1.11.1
1.11.4

Open the chart page →

1,945
elasticsearchwiremindVerified publisher8.19.11 of 1See more

elasticsearch wiremind 8.19.1

1 of the 1 container images this version deploys carry CVE-2026-106450.

Container imageDigestPackageFixed in
library/elasticsearch:8.19.22d071f96fab6c
lz4-java@1.11.1
1.11.4

Open the chart page →

687
metabasewiremindVerified publisher2.27.5-wiremind01 of 1See more

metabase wiremind 2.27.5-wiremind0

1 of the 1 container images this version deploys carry CVE-2026-106450.

Container imageDigestPackageFixed in
metabase/metabase:v0.61.1.x9491ed11c901
lz4-java@1.10.4
1.11.4

Open the chart page →

1,878
zipkinzipkinVerified publisher0.5.01 of 1See more

zipkin zipkin 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-106450.

Container imageDigestPackageFixed in
openzipkin/zipkin-slim:3.6.0a69e1057df36
lz4-java@1.10.1
1.11.4

Open the chart page →

1,403

Container images carrying it

113 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2:8.2.2-1-ubi98e01c0305844
lz4-java@1.10.1
1.11.4
7
airbyte/workload-launcher:2.3.00e18b1abcda6
lz4-java@1.11.1
1.11.4
2
apache/druid:37.0.00116fb802786
lz4-java@1.10.2
1.11.4
2
apache/kafka:4.3.177e3df905404
lz4-java@1.10.2
1.11.4
2
datagrok/grok_connect:latestf5876d3aebb8
lz4-java@1.10.1
1.11.4
2
graviteeio/apim-gateway:4.12.21-debianc7564f313dda
lz4-java@1.10.1
1.11.4
2
graviteeio/apim-management-api:4.12.21-debian3caf0b09f8b5
lz4-java@1.10.1
1.11.4
2
library/elasticsearch:8.19.22d071f96fab6c
lz4-java@1.11.1
1.11.4
2
metabase/metabase:v0.61.1.x9491ed11c901
lz4-java@1.10.4
1.11.4
2
ghcr.io/kafbat/kafka-ui:v1.5.07cda86a33344
lz4-java@1.10.1
1.11.4
2
ghcr.io/quenchworks/images/akhqf3dddad78840
lz4-java@1.11.1
1.11.4
2
ghcr.io/quenchworks/images/cassandra2828b88f226a
lz4-java@1.11.1
1.11.4
2
ghcr.io/quenchworks/images/kafkaa2a8f8c1845b
lz4-java@1.11.1
1.11.4
2
ghcr.io/quenchworks/images/trinob88f74961479
lz4-java@1.11.1
1.11.4
2
public.ecr.aws/aktosecurity/akto-api-security-dashboard:1.70.3:latest142caa08d1f0
lz4-java@1.10.1
1.11.4
2
quay.io/strimzi/operator:1.2.077f8fa8121a6
lz4-java@1.10.2
1.11.4
2
acryldata/datahub-frontend-react:v1.7.0.199513cc1c45e
lz4-java@1.11.1
1.11.4
1
acryldata/datahub-upgrade:v1.7.0.1c3db54d8fb94
lz4-java@1.11.1
1.11.4
1
aerospike/aerospike-graph-service:3.3.1781ba5213efd
lz4-java@1.11.2
1.11.4
1
aerospike/aerospike-graph-service:3.3.0f35739b97a46
lz4-java@1.11.2
1.11.4
1
airbyte/bootloader:2.3.0205b99d17c1a
lz4-java@1.11.1
1.11.4
1
airbyte/server:2.3.039141ed8ce5e
lz4-java@1.11.1
1.11.4
1
airbyte/worker:2.3.0f2e33fbc53d1
lz4-java@1.11.1
1.11.4
1
airbyte/workload-api-server:2.3.0434b4a811156
lz4-java@1.11.1
1.11.4
1
aktosecurity/akto-api-security-dashboard:latest9ef5e8cb6a43
lz4-java@1.10.1
1.11.4
1
aktosecurity/akto-threat-detection-backend:1.18.75a0c66e59678
lz4-java@1.10.1
1.11.4
1
aktosecurity/akto-threat-detection-backend:latestd9d0e7c78578
lz4-java@1.10.1
1.11.4
1
aktosecurity/data-ingestion-service:1.5.35d4eab1c36b9
lz4-java@1.10.1
1.11.4
1
apache/polaris:latest347615e736ca
lz4-java@1.11.1
1.11.4
1
confluentinc/cp-cmf:2.4.3c7617bf49a1b
lz4-java@1.11.1
1.11.4
1
confluentinc/cp-kafka:latest5e8f3ab5b497
lz4-java@1.11.1
1.11.4
1
confluentinc/cp-schema-registry:latest482d3048b3f6
lz4-java@1.11.1
1.11.4
1
dbeaver/cloudbeaver:26.1.287ab86d00f8c
lz4-java@1.10.1
1.11.4
1
factorhouse/factor-platform:96.5b19f8edcb778
lz4-java@1.11.1
1.11.4
1
factorhouse/kpow:96.55994fa3bacce
lz4-java@1.11.1
1.11.4
1
factorhouse/kpow-ce:96.5b1d5f1eea44c
lz4-java@1.11.1
1.11.4
1
folioci/mod-agreements:latest29c3f233a498
lz4-java@1.10.1
1.11.4
1
folioci/mod-audit:latest88f40730ed45
lz4-java@1.10.1
1.11.4
1
folioci/mod-circulation:latest3eecd2ac2d8a
lz4-java@1.10.1
1.11.4
1
folioci/mod-circulation-storage:latest6bdddcafbc0f
lz4-java@1.10.1
1.11.4
1
folioci/mod-data-export-spring:latestf1d7caf4544b
lz4-java@1.10.1
1.11.4
1
folioci/mod-data-export-worker:latest1ad1811c9b37
lz4-java@1.10.1
1.11.4
1
folioci/mod-data-import:latestec2c3ebe3f2b
lz4-java@1.10.2
1.11.4
1
folioci/mod-entities-links:latest3e2412815c0f
lz4-java@1.10.1
1.11.4
1
folioci/mod-inn-reach:latestcc8584e43382
lz4-java@1.10.1
1.11.4
1
folioci/mod-inventory:latest53518ba29668
lz4-java@1.10.2
1.11.4
1
folioci/mod-inventory-storage:latestf92ff0a3ca40
lz4-java@1.10.1
1.11.4
1
folioci/mod-invoice:latest45b7b13e81e1
lz4-java@1.10.1
1.11.4
1
folioci/mod-invoice-storage:latest0bc720abcb78
lz4-java@1.10.1
1.11.4
1
folioci/mod-licenses:latestcfd6109bf477
lz4-java@1.10.1
1.11.4
1

syft 1.42.1 · advisories as of 8 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.