StackRadar

CVE-2026-106451

High

Advisory

Published 7 Oct 2026In the index since 8 Oct 2026
Severity
High
worst across findings
CVSS
7.3
base score, highest
EPSS
0.001
0th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
113
of 18,053 indexed, latest versions
Container images
113
deployed by those charts
Fix available
1 of 1
affected package

yawkat LZ4 Java: Native library extraction to a shared temporary directory is vulnerable to file replacement by another local user

Carried by container images the latest versions of 113 of 18,053 indexed charts deploy, on 113 images.

Affected packageAffected versionsFixed inImages
lz4-javamaven1.10.1, 1.10.2, 1.10.4, 1.11.0+2 more1.11.4113
OSV records
GHSA-mcr4-qmvw-px4g

Charts affected

113 by stars
ChartLatestAffected imagesRadar Score
eximeebpmseximeebpms-k8sOfficialVerified publisher0.4.11 of 1See more

eximeebpms eximeebpms-k8s 0.4.1

1 of the 1 container images this version deploys carry CVE-2026-106451.

Container imageDigestPackageFixed in
ghcr.io/eximeebpms/eximeebpms-bpm-platform:run-1.4.00f4a5c0eea07
lz4-java@1.11.2
1.11.4

Open the chart page →

287
factor-platformfactorhouseVerified publisher0.0.51 of 1See more

factor-platform factorhouse 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-106451.

Container imageDigestPackageFixed in
factorhouse/factor-platform:96.5b19f8edcb778
lz4-java@1.11.1
1.11.4

Open the chart page →

139
mod-agreementsfolio-org0.1.321 of 1See more

mod-agreements folio-org 0.1.32

1 of the 1 container images this version deploys carry CVE-2026-106451.

Container imageDigestPackageFixed in
folioci/mod-agreements:latest29c3f233a498
lz4-java@1.10.1
1.11.4

Open the chart page →

1,902
mod-auditfolio-org0.1.361 of 1See more

mod-audit folio-org 0.1.36

1 of the 1 container images this version deploys carry CVE-2026-106451.

Container imageDigestPackageFixed in
folioci/mod-audit:latest88f40730ed45
lz4-java@1.10.1
1.11.4

Open the chart page →

267
mod-circulationfolio-org0.1.351 of 1See more

mod-circulation folio-org 0.1.35

1 of the 1 container images this version deploys carry CVE-2026-106451.

Container imageDigestPackageFixed in
folioci/mod-circulation:latest3eecd2ac2d8a
lz4-java@1.10.1
1.11.4

Open the chart page →

500
mod-circulation-storagefolio-org0.1.351 of 1See more

mod-circulation-storage folio-org 0.1.35

1 of the 1 container images this version deploys carry CVE-2026-106451.

Container imageDigestPackageFixed in
folioci/mod-circulation-storage:latest6bdddcafbc0f
lz4-java@1.10.1
1.11.4

Open the chart page →

662
mod-data-export-springfolio-org0.1.41 of 1See more

mod-data-export-spring folio-org 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-106451.

Container imageDigestPackageFixed in
folioci/mod-data-export-spring:latestf1d7caf4544b
lz4-java@1.10.1
1.11.4

Open the chart page →

1,258
mod-data-export-workerfolio-org0.1.151 of 1See more

mod-data-export-worker folio-org 0.1.15

1 of the 1 container images this version deploys carry CVE-2026-106451.

Container imageDigestPackageFixed in
folioci/mod-data-export-worker:latest1ad1811c9b37
lz4-java@1.10.1
1.11.4

Open the chart page →

1,244
mod-data-importfolio-org0.1.381 of 1See more

mod-data-import folio-org 0.1.38

1 of the 1 container images this version deploys carry CVE-2026-106451.

Container imageDigestPackageFixed in
folioci/mod-data-import:latestec2c3ebe3f2b
lz4-java@1.10.2
1.11.4

Open the chart page →

11
mod-entities-linksfolio-org0.1.11 of 1See more

mod-entities-links folio-org 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-106451.

Container imageDigestPackageFixed in
folioci/mod-entities-links:latest3e2412815c0f
lz4-java@1.10.1
1.11.4

Open the chart page →

312
mod-inn-reachfolio-org0.1.71 of 1See more

mod-inn-reach folio-org 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-106451.

Container imageDigestPackageFixed in
folioci/mod-inn-reach:latestcc8584e43382
lz4-java@1.10.1
1.11.4

Open the chart page →

513
mod-inventoryfolio-org0.1.361 of 1See more

mod-inventory folio-org 0.1.36

1 of the 1 container images this version deploys carry CVE-2026-106451.

Container imageDigestPackageFixed in
folioci/mod-inventory:latest53518ba29668
lz4-java@1.10.2
1.11.4

Open the chart page →

33
mod-inventory-storagefolio-org0.1.371 of 1See more

mod-inventory-storage folio-org 0.1.37

1 of the 1 container images this version deploys carry CVE-2026-106451.

Container imageDigestPackageFixed in
folioci/mod-inventory-storage:latestf92ff0a3ca40
lz4-java@1.10.1
1.11.4

Open the chart page →

81
mod-invoicefolio-org0.1.351 of 1See more

mod-invoice folio-org 0.1.35

1 of the 1 container images this version deploys carry CVE-2026-106451.

Container imageDigestPackageFixed in
folioci/mod-invoice:latest45b7b13e81e1
lz4-java@1.10.1
1.11.4

Open the chart page →

571
mod-invoice-storagefolio-org0.1.341 of 1See more

mod-invoice-storage folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-106451.

Container imageDigestPackageFixed in
folioci/mod-invoice-storage:latest0bc720abcb78
lz4-java@1.10.1
1.11.4

Open the chart page →

226
mod-licensesfolio-org0.1.321 of 1See more

mod-licenses folio-org 0.1.32

1 of the 1 container images this version deploys carry CVE-2026-106451.

Container imageDigestPackageFixed in
folioci/mod-licenses:latestcfd6109bf477
lz4-java@1.10.1
1.11.4

Open the chart page →

1,787
mod-notesfolio-org0.1.341 of 1See more

mod-notes folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-106451.

Container imageDigestPackageFixed in
folioci/mod-notes:latest998ac4782e0d
lz4-java@1.10.1
1.11.4

Open the chart page →

157
mod-oafolio-org0.1.21 of 1See more

mod-oa folio-org 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-106451.

Container imageDigestPackageFixed in
folioci/mod-oa:latestae3b069d4ba5
lz4-java@1.10.1
1.11.4

Open the chart page →

1,735
mod-ordersfolio-org0.1.341 of 1See more

mod-orders folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-106451.

Container imageDigestPackageFixed in
folioci/mod-orders:latestfc4528220fb8
lz4-java@1.10.1
1.11.4

Open the chart page →

458
mod-orders-storagefolio-org0.1.351 of 1See more

mod-orders-storage folio-org 0.1.35

1 of the 1 container images this version deploys carry CVE-2026-106451.

Container imageDigestPackageFixed in
folioci/mod-orders-storage:latestceeaacc3bf16
lz4-java@1.10.1
1.11.4

Open the chart page →

443
mod-organizations-storagefolio-org0.1.341 of 1See more

mod-organizations-storage folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-106451.

Container imageDigestPackageFixed in
folioci/mod-organizations-storage:lateste46892405fde
lz4-java@1.10.1
1.11.4

Open the chart page →

670
mod-patron-blocksfolio-org0.1.341 of 1See more

mod-patron-blocks folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-106451.

Container imageDigestPackageFixed in
folioci/mod-patron-blocks:latestde7318069a67
lz4-java@1.10.1
1.11.4

Open the chart page →

360
mod-pubsubfolio-org0.1.341 of 1See more

mod-pubsub folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-106451.

Container imageDigestPackageFixed in
folioci/mod-pubsub:latest0a4fa4ad5d72
lz4-java@1.10.1
1.11.4

Open the chart page →

1,017
mod-quick-marcfolio-org0.1.351 of 1See more

mod-quick-marc folio-org 0.1.35

1 of the 1 container images this version deploys carry CVE-2026-106451.

Container imageDigestPackageFixed in
folioci/mod-quick-marc:latest4d70ebda4d00
lz4-java@1.10.1
1.11.4

Open the chart page →

63
mod-remote-storagefolio-org0.1.321 of 1See more

mod-remote-storage folio-org 0.1.32

1 of the 1 container images this version deploys carry CVE-2026-106451.

Container imageDigestPackageFixed in
folioci/mod-remote-storage:latest4f12177123dc
lz4-java@1.10.1
1.11.4

Open the chart page →

572
mod-searchfolio-org0.1.351 of 1See more

mod-search folio-org 0.1.35

1 of the 1 container images this version deploys carry CVE-2026-106451.

Container imageDigestPackageFixed in
folioci/mod-search:latest44d7ee9acdf6
lz4-java@1.10.1
1.11.4

Open the chart page →

1,561
mod-serials-managementfolio-org0.1.11 of 1See more

mod-serials-management folio-org 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-106451.

Container imageDigestPackageFixed in
folioci/mod-serials-management:latest571fa1ffe8c9
lz4-java@1.10.1
1.11.4

Open the chart page →

1,735
mod-service-interactionfolio-org0.1.61 of 1See more

mod-service-interaction folio-org 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-106451.

Container imageDigestPackageFixed in
folioci/mod-service-interaction:latestf53c327a48e8
lz4-java@1.10.1
1.11.4

Open the chart page →

1,735
mod-source-record-managerfolio-org0.1.371 of 1See more

mod-source-record-manager folio-org 0.1.37

1 of the 1 container images this version deploys carry CVE-2026-106451.

Container imageDigestPackageFixed in
folioci/mod-source-record-manager:latesta940caf026ee
lz4-java@1.10.2
1.11.4

Open the chart page →

59
mod-source-record-storagefolio-org0.1.371 of 1See more

mod-source-record-storage folio-org 0.1.37

1 of the 1 container images this version deploys carry CVE-2026-106451.

Container imageDigestPackageFixed in
folioci/mod-source-record-storage:latesta1434881eeb7
lz4-java@1.10.1
1.11.4

Open the chart page →

11
mod-usersfolio-org0.1.341 of 1See more

mod-users folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-106451.

Container imageDigestPackageFixed in
folioci/mod-users:latest6f60033321b0
lz4-java@1.10.2
1.11.4

Open the chart page →

432
druidhelmforgeVerified publisher1.3.61 of 4See more

druid helmforge 1.3.6

1 of the 4 container images this version deploys carry CVE-2026-106451.

Container imageDigestPackageFixed in
apache/druid:37.0.00116fb802786
lz4-java@1.10.2
1.11.4

Open the chart page →

9,667
elasticsearchhelmforgeVerified publisher1.1.81 of 2See more

elasticsearch helmforge 1.1.8

1 of the 2 container images this version deploys carry CVE-2026-106451.

Container imageDigestPackageFixed in
library/elasticsearch:9.5.3a4e2b3d21ad0
lz4-java@1.11.1
1.11.4

Open the chart page →

484
kibanahelmforgeVerified publisher1.1.81 of 3See more

kibana helmforge 1.1.8

1 of the 3 container images this version deploys carry CVE-2026-106451.

Container imageDigestPackageFixed in
library/elasticsearch:9.5.19656a9ca03f8
lz4-java@1.11.1
1.11.4

Open the chart page →

602
metabasehelmforgeVerified publisher1.2.301 of 3See more

metabase helmforge 1.2.30

1 of the 3 container images this version deploys carry CVE-2026-106451.

Container imageDigestPackageFixed in
metabase/metabase:v0.63.181160b570cb11
lz4-java@1.10.4
1.11.4

Open the chart page →

1,842
ibm-events-operatoribm-helm6.0.0+20260126.110734.01 of 1See more

ibm-events-operator ibm-helm 6.0.0+20260126.110734.0

1 of the 1 container images this version deploys carry CVE-2026-106451.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:latest60abcb19699f
lz4-java@1.10.2
1.11.4

Open the chart page →

99
thehiveittrident-oss0.1.01 of 6See more

thehive ittrident-oss 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-106451.

Container imageDigestPackageFixed in
library/cassandra:4.03a4876cc7f18
lz4-java@1.10.1
1.11.4

Open the chart page →

7,173
kannikakannika0.19.01 of 3See more

kannika kannika 0.19.0

1 of the 3 container images this version deploys carry CVE-2026-106451.

Container imageDigestPackageFixed in
quay.io/kannika/kannika-api:0.19.05e5a3b3a911e
lz4-java@1.10.2
1.11.4

Open the chart page →

1,037
klagklagVerified publisher0.3.171 of 1See more

klag klag 0.3.17

1 of the 1 container images this version deploys carry CVE-2026-106451.

Container imageDigestPackageFixed in
themoah/klag:0.2.187178531ebe86
lz4-java@1.11.1
1.11.4

Open the chart page →

646
sentinelopennms-helm-chartsVerified publisher0.5.01 of 2See more

sentinel opennms-helm-charts 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-106451.

Container imageDigestPackageFixed in
opennms/sentinel:36.0.4e1880996623f
lz4-java@1.10.2
1.11.4

Open the chart page →

2,175
cp-cmfopenshift2.4.31 of 1See more

cp-cmf openshift 2.4.3

1 of the 1 container images this version deploys carry CVE-2026-106451.

Container imageDigestPackageFixed in
confluentinc/cp-cmf:2.4.3c7617bf49a1b
lz4-java@1.11.1
1.11.4

Open the chart page →

98
trinoopstty0.2.141 of 1See more

trino opstty 0.2.14

1 of the 1 container images this version deploys carry CVE-2026-106451.

Container imageDigestPackageFixed in
trinodb/trino:4815b5e0a97f599
lz4-java@1.11.0
1.11.4

Open the chart page →

1,510
akhqquench-akhqVerified publisher0.0.51 of 1See more

akhq quench-akhq 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-106451.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/akhqdigest-pinnedf3dddad78840
lz4-java@1.11.1
1.11.4

Open the chart page →

83
cadencequench-cadenceVerified publisher0.0.221 of 2See more

cadence quench-cadence 0.0.22

1 of the 2 container images this version deploys carry CVE-2026-106451.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/cassandradigest-pinned2828b88f226a
lz4-java@1.11.1
1.11.4

Open the chart page →

99
cassandraquench-cassandraVerified publisher0.0.241 of 1See more

cassandra quench-cassandra 0.0.24

1 of the 1 container images this version deploys carry CVE-2026-106451.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/cassandradigest-pinned2828b88f226a
lz4-java@1.11.1
1.11.4

Open the chart page →

83
elasticsearchquench-elasticsearchVerified publisher0.0.231 of 1See more

elasticsearch quench-elasticsearch 0.0.23

1 of the 1 container images this version deploys carry CVE-2026-106451.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/elasticsearchdigest-pinned6ec7ad24d45c
lz4-java@1.11.1
1.11.4

Open the chart page →

83
kafkaquench-kafkaVerified publisher0.0.221 of 1See more

kafka quench-kafka 0.0.22

1 of the 1 container images this version deploys carry CVE-2026-106451.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/kafkadigest-pinneda2a8f8c1845b
lz4-java@1.11.1
1.11.4

Open the chart page →

83
lakehouse-stackquench-lakehouse-stackVerified publisher0.0.121 of 4See more

lakehouse-stack quench-lakehouse-stack 0.0.12

1 of the 4 container images this version deploys carry CVE-2026-106451.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/trinodigest-pinnedb88f74961479
lz4-java@1.11.1
1.11.4

Open the chart page →

179
metabasequench-metabase0.0.61 of 2See more

metabase quench-metabase 0.0.6

1 of the 2 container images this version deploys carry CVE-2026-106451.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/metabasedigest-pinned2024b60e8b2f
lz4-java@1.11.1
1.11.4

Open the chart page →

152
nifiquench-nifiVerified publisher0.0.51 of 1See more

nifi quench-nifi 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-106451.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/nifidigest-pinnedac51c98e9e37
lz4-java@1.11.2
1.11.4

Open the chart page →

135

Container images carrying it

113 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/quenchworks/images/nifiac51c98e9e37
lz4-java@1.11.2
1.11.4
1
ghcr.io/quenchworks/images/pulsar1b3a533f6607
lz4-java@1.11.1
1.11.4
1
ghcr.io/quenchworks/images/skywalkingb234844163cf
lz4-java@1.11.2
1.11.4
1
ghcr.io/quenchworks/images/wildfly51c31ca1bc16
lz4-java@1.11.2
1.11.4
1
ghcr.io/quenchworks/images/zipkincd4d4af2076b
lz4-java@1.11.1
1.11.4
1
ghcr.io/radar-base/radar-gateway/radar-gateway:0.9.4219d894aa7a6
lz4-java@1.10.1
1.11.4
1
ghcr.io/radar-base/radar-schemas/radar-schemas-tools:0.8.16c442e8bfe6b4
lz4-java@1.10.1
1.11.4
1
public.ecr.aws/aktosecurity/akto-api-security-database-abstractor:1.70.366b0ec8b3de3
lz4-java@1.10.1
1.11.4
1
public.ecr.aws/aktosecurity/akto-api-security-runtime:latestc89a1c10c9c2
lz4-java@1.10.1
1.11.4
1
public.ecr.aws/aktosecurity/akto-threat-detection:1.18.755b1bd20ef02
lz4-java@1.10.1
1.11.4
1
public.ecr.aws/aktosecurity/akto-threat-detection:latestf14d68a2b1cf
lz4-java@1.10.1
1.11.4
1
quay.io/kannika/kannika-api:0.19.05e5a3b3a911e
lz4-java@1.10.2
1.11.4
1
quay.io/strimzi/operator:latest60abcb19699f
lz4-java@1.10.2
1.11.4
1

syft 1.42.1 · advisories as of 8 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.