StackRadar

CVE-2026-106453

Medium

Advisory

Published 7 Oct 2026In the index since 8 Oct 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
29th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
104
of 18,053 indexed, latest versions
Container images
103
deployed by those charts
Fix available
1 of 1
affected package

yawkat LZ4 Java: LZ4DecompressorWithLength allocates the unvalidated size from the 4-byte length header, so a 5-byte input triggers a 1 GiB allocation and OutOfMemoryError

Carried by container images the latest versions of 104 of 18,053 indexed charts deploy, on 103 images.

Affected packageAffected versionsFixed inImages
lz4-javamaven1.10.1, 1.10.2, 1.10.4, 1.11.0+1 more1.11.2103
OSV records
GHSA-6cx8-rjf8-pr8g

Charts affected

104 by stars
ChartLatestAffected imagesRadar Score
kafkatwomartensVerified publisher0.2.11 of 2See more

kafka twomartens 0.2.1

1 of the 2 container images this version deploys carry CVE-2026-106453.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:latest5e8f3ab5b497
lz4-java@1.11.1
1.11.2

Open the chart page →

1,945
elasticsearchwiremindVerified publisher8.19.11 of 1See more

elasticsearch wiremind 8.19.1

1 of the 1 container images this version deploys carry CVE-2026-106453.

Container imageDigestPackageFixed in
library/elasticsearch:8.19.22d071f96fab6c
lz4-java@1.11.1
1.11.2

Open the chart page →

687
metabasewiremindVerified publisher2.27.5-wiremind01 of 1See more

metabase wiremind 2.27.5-wiremind0

1 of the 1 container images this version deploys carry CVE-2026-106453.

Container imageDigestPackageFixed in
metabase/metabase:v0.61.1.x9491ed11c901
lz4-java@1.10.4
1.11.2

Open the chart page →

1,878
zipkinzipkinVerified publisher0.5.01 of 1See more

zipkin zipkin 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-106453.

Container imageDigestPackageFixed in
openzipkin/zipkin-slim:3.6.0a69e1057df36
lz4-java@1.10.1
1.11.2

Open the chart page →

1,403

Container images carrying it

103 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
public.ecr.aws/aktosecurity/akto-threat-detection:latestf14d68a2b1cf
lz4-java@1.10.1
1.11.2
1
quay.io/kannika/kannika-api:0.19.05e5a3b3a911e
lz4-java@1.10.2
1.11.2
1
quay.io/strimzi/operator:latest60abcb19699f
lz4-java@1.10.2
1.11.2
1

syft 1.42.1 · advisories as of 8 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.