StackRadar

CVE-2026-106453

Medium

Advisory

Published 7 Oct 2026In the index since 8 Oct 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
29th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
104
of 18,053 indexed, latest versions
Container images
103
deployed by those charts
Fix available
1 of 1
affected package

yawkat LZ4 Java: LZ4DecompressorWithLength allocates the unvalidated size from the 4-byte length header, so a 5-byte input triggers a 1 GiB allocation and OutOfMemoryError

Carried by container images the latest versions of 104 of 18,053 indexed charts deploy, on 103 images.

Affected packageAffected versionsFixed inImages
lz4-javamaven1.10.1, 1.10.2, 1.10.4, 1.11.0+1 more1.11.2103
OSV records
GHSA-6cx8-rjf8-pr8g

Charts affected

104 by stars
ChartLatestAffected imagesRadar Score
kafkatwomartensVerified publisher0.2.11 of 2See more

kafka twomartens 0.2.1

1 of the 2 container images this version deploys carry CVE-2026-106453.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:latest5e8f3ab5b497
lz4-java@1.11.1
1.11.2

Open the chart page →

1,945
elasticsearchwiremindVerified publisher8.19.11 of 1See more

elasticsearch wiremind 8.19.1

1 of the 1 container images this version deploys carry CVE-2026-106453.

Container imageDigestPackageFixed in
library/elasticsearch:8.19.22d071f96fab6c
lz4-java@1.11.1
1.11.2

Open the chart page →

687
metabasewiremindVerified publisher2.27.5-wiremind01 of 1See more

metabase wiremind 2.27.5-wiremind0

1 of the 1 container images this version deploys carry CVE-2026-106453.

Container imageDigestPackageFixed in
metabase/metabase:v0.61.1.x9491ed11c901
lz4-java@1.10.4
1.11.2

Open the chart page →

1,878
zipkinzipkinVerified publisher0.5.01 of 1See more

zipkin zipkin 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-106453.

Container imageDigestPackageFixed in
openzipkin/zipkin-slim:3.6.0a69e1057df36
lz4-java@1.10.1
1.11.2

Open the chart page →

1,403

Container images carrying it

103 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
folioci/mod-orders:latestfc4528220fb8
lz4-java@1.10.1
1.11.2
1
folioci/mod-orders-storage:latestceeaacc3bf16
lz4-java@1.10.1
1.11.2
1
folioci/mod-organizations-storage:lateste46892405fde
lz4-java@1.10.1
1.11.2
1
folioci/mod-patron-blocks:latestde7318069a67
lz4-java@1.10.1
1.11.2
1
folioci/mod-pubsub:latest0a4fa4ad5d72
lz4-java@1.10.1
1.11.2
1
folioci/mod-quick-marc:latest4d70ebda4d00
lz4-java@1.10.1
1.11.2
1
folioci/mod-remote-storage:latest4f12177123dc
lz4-java@1.10.1
1.11.2
1
folioci/mod-search:latest44d7ee9acdf6
lz4-java@1.10.1
1.11.2
1
folioci/mod-serials-management:latest571fa1ffe8c9
lz4-java@1.10.1
1.11.2
1
folioci/mod-service-interaction:latestf53c327a48e8
lz4-java@1.10.1
1.11.2
1
folioci/mod-source-record-manager:latesta940caf026ee
lz4-java@1.10.2
1.11.2
1
folioci/mod-source-record-storage:latesta1434881eeb7
lz4-java@1.10.1
1.11.2
1
folioci/mod-users:latest6f60033321b0
lz4-java@1.10.2
1.11.2
1
graviteeio/am-gateway:4.12.8d09cf41530da
lz4-java@1.10.1
1.11.2
1
graviteeio/am-management-api:4.12.849d0188a58ae
lz4-java@1.10.1
1.11.2
1
graylog/graylog:7.1.9598bd41fefd5
lz4-java@1.10.4
1.11.2
1
graylog/graylog-enterprise:7.1.88a1f641cd7aa
lz4-java@1.10.4
1.11.2
1
hazelcast/hazelcast:latestf086bf0ecb23
lz4-java@1.10.1
1.11.2
1
hazelcast/hazelcast-enterprise:5.7.1cdff425edc10
lz4-java@1.10.1
1.11.2
1
library/cassandra:4.03a4876cc7f18
lz4-java@1.10.1
1.11.2
1
library/elasticsearch:9.5.19656a9ca03f8
lz4-java@1.11.1
1.11.2
1
library/elasticsearch:9.5.3a4e2b3d21ad0
lz4-java@1.11.1
1.11.2
1
library/neo4j:2026.05.0-enterprise2caf944aa4a5
lz4-java@1.11.0
1.11.2
1
metabase/metabase:v0.63.181160b570cb11
lz4-java@1.10.4
1.11.2
1
metabase/metabase:v0.63.1.124f150effd484
lz4-java@1.10.4
1.11.2
1
metabase/metabase:latestb7c6250d7fd2
lz4-java@1.10.4
1.11.2
1
opennms/sentinel:36.0.4e1880996623f
lz4-java@1.10.2
1.11.2
1
opensearchproject/opensearch:2.19.6e321cb03c643
lz4-java@1.10.1
1.11.2
1
openzipkin/zipkin-slim:3.6.0a69e1057df36
lz4-java@1.10.1
1.11.2
1
tchiotludo/akhq:0.28.0c2824dc2ae44
lz4-java@1.11.1
1.11.2
1
themoah/klag:0.2.187178531ebe86
lz4-java@1.11.1
1.11.2
1
thingsboard/tb-postgres:latest2d17e4e36edc
lz4-java@1.10.1
1.11.2
1
trinodb/trino:4801565e8cac299
lz4-java@1.10.4
1.11.2
1
trinodb/trino:4815b5e0a97f599
lz4-java@1.11.0
1.11.2
1
ghcr.io/comet-ml/opik/opik-backend:2.2.94809d837a1dcf
lz4-java@1.10.4
1.11.2
1
ghcr.io/gla-rad/enav-aton-admin-service:latest8b963221a007
lz4-java@1.10.1
1.11.2
1
ghcr.io/gla-rad/enav-aton-service:latest3ffe10cd9cef
lz4-java@1.10.1
1.11.2
1
ghcr.io/gla-rad/enav-msg-broker:latest5c0966fa0257
lz4-java@1.10.1
1.11.2
1
ghcr.io/kubelauncher/cassandra4a2625365fc6
lz4-java@1.10.1
1.11.2
1
ghcr.io/open-telemetry/demo:3.1.0-kafka4402ba7fd544
lz4-java@1.10.2
1.11.2
1
ghcr.io/open-telemetry/demo:3.1.0-fraud-detectiona07ee694304b
lz4-java@1.10.2
1.11.2
1
ghcr.io/quenchworks/images/elasticsearch6ec7ad24d45c
lz4-java@1.11.1
1.11.2
1
ghcr.io/quenchworks/images/metabase2024b60e8b2f
lz4-java@1.11.1
1.11.2
1
ghcr.io/quenchworks/images/pulsar1b3a533f6607
lz4-java@1.11.1
1.11.2
1
ghcr.io/quenchworks/images/zipkincd4d4af2076b
lz4-java@1.11.1
1.11.2
1
ghcr.io/radar-base/radar-gateway/radar-gateway:0.9.4219d894aa7a6
lz4-java@1.10.1
1.11.2
1
ghcr.io/radar-base/radar-schemas/radar-schemas-tools:0.8.16c442e8bfe6b4
lz4-java@1.10.1
1.11.2
1
public.ecr.aws/aktosecurity/akto-api-security-database-abstractor:1.70.366b0ec8b3de3
lz4-java@1.10.1
1.11.2
1
public.ecr.aws/aktosecurity/akto-api-security-runtime:latestc89a1c10c9c2
lz4-java@1.10.1
1.11.2
1
public.ecr.aws/aktosecurity/akto-threat-detection:1.18.755b1bd20ef02
lz4-java@1.10.1
1.11.2
1

syft 1.42.1 · advisories as of 8 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.