StackRadar

CVE-2026-59949

Medium

Advisory

Published 24 Jul 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.005
38th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
89
of 17,781 indexed, latest versions
Container images
87
deployed by those charts
Fix available
1 of 1
affected package

LZ4 Java: Native XXHash implementations can crash the JVM when passed invalid byte array ranges

Carried by container images the latest versions of 89 of 17,781 indexed charts deploy, on 87 images.

Affected packageAffected versionsFixed inImages
lz4-javamaven1.10.1, 1.10.2, 1.10.4, 1.11.01.11.187
OSV records
GHSA-xx22-p4ch-683r

Charts affected

89 by stars
ChartLatestAffected imagesRadar Score
mod-data-export-workerfolio-org0.1.151 of 1See more

mod-data-export-worker folio-org 0.1.15

1 of the 1 container images this version deploys carry CVE-2026-59949.

Container imageDigestPackageFixed in
folioci/mod-data-export-worker:latest1ad1811c9b37
lz4-java@1.10.1
1.11.1

Open the chart page →

1,214
mod-data-importfolio-org0.1.381 of 1See more

mod-data-import folio-org 0.1.38

1 of the 1 container images this version deploys carry CVE-2026-59949.

Container imageDigestPackageFixed in
folioci/mod-data-import:latestec2c3ebe3f2b
lz4-java@1.10.2
1.11.1

Open the chart page →

11
mod-entities-linksfolio-org0.1.11 of 1See more

mod-entities-links folio-org 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-59949.

Container imageDigestPackageFixed in
folioci/mod-entities-links:latest3e2412815c0f
lz4-java@1.10.1
1.11.1

Open the chart page →

285
mod-inn-reachfolio-org0.1.71 of 1See more

mod-inn-reach folio-org 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-59949.

Container imageDigestPackageFixed in
folioci/mod-inn-reach:latestcc8584e43382
lz4-java@1.10.1
1.11.1

Open the chart page →

512
mod-inventoryfolio-org0.1.361 of 1See more

mod-inventory folio-org 0.1.36

1 of the 1 container images this version deploys carry CVE-2026-59949.

Container imageDigestPackageFixed in
folioci/mod-inventory:latest53518ba29668
lz4-java@1.10.2
1.11.1

Open the chart page →

33
mod-inventory-storagefolio-org0.1.371 of 1See more

mod-inventory-storage folio-org 0.1.37

1 of the 1 container images this version deploys carry CVE-2026-59949.

Container imageDigestPackageFixed in
folioci/mod-inventory-storage:latestf92ff0a3ca40
lz4-java@1.10.1
1.11.1

Open the chart page →

81
mod-invoicefolio-org0.1.351 of 1See more

mod-invoice folio-org 0.1.35

1 of the 1 container images this version deploys carry CVE-2026-59949.

Container imageDigestPackageFixed in
folioci/mod-invoice:latest45b7b13e81e1
lz4-java@1.10.1
1.11.1

Open the chart page →

568
mod-invoice-storagefolio-org0.1.341 of 1See more

mod-invoice-storage folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-59949.

Container imageDigestPackageFixed in
folioci/mod-invoice-storage:latest0bc720abcb78
lz4-java@1.10.1
1.11.1

Open the chart page →

225
mod-licensesfolio-org0.1.321 of 1See more

mod-licenses folio-org 0.1.32

1 of the 1 container images this version deploys carry CVE-2026-59949.

Container imageDigestPackageFixed in
folioci/mod-licenses:latestcfd6109bf477
lz4-java@1.10.1
1.11.1

Open the chart page →

1,760
mod-notesfolio-org0.1.341 of 1See more

mod-notes folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-59949.

Container imageDigestPackageFixed in
folioci/mod-notes:latest998ac4782e0d
lz4-java@1.10.1
1.11.1

Open the chart page →

156
mod-oafolio-org0.1.21 of 1See more

mod-oa folio-org 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-59949.

Container imageDigestPackageFixed in
folioci/mod-oa:latestae3b069d4ba5
lz4-java@1.10.1
1.11.1

Open the chart page →

1,733
mod-ordersfolio-org0.1.341 of 1See more

mod-orders folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-59949.

Container imageDigestPackageFixed in
folioci/mod-orders:latestfc4528220fb8
lz4-java@1.10.1
1.11.1

Open the chart page →

456
mod-orders-storagefolio-org0.1.351 of 1See more

mod-orders-storage folio-org 0.1.35

1 of the 1 container images this version deploys carry CVE-2026-59949.

Container imageDigestPackageFixed in
folioci/mod-orders-storage:latestceeaacc3bf16
lz4-java@1.10.1
1.11.1

Open the chart page →

442
mod-organizations-storagefolio-org0.1.341 of 1See more

mod-organizations-storage folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-59949.

Container imageDigestPackageFixed in
folioci/mod-organizations-storage:lateste46892405fde
lz4-java@1.10.1
1.11.1

Open the chart page →

665
mod-patron-blocksfolio-org0.1.341 of 1See more

mod-patron-blocks folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-59949.

Container imageDigestPackageFixed in
folioci/mod-patron-blocks:latestde7318069a67
lz4-java@1.10.1
1.11.1

Open the chart page →

359
mod-pubsubfolio-org0.1.341 of 1See more

mod-pubsub folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-59949.

Container imageDigestPackageFixed in
folioci/mod-pubsub:latest0a4fa4ad5d72
lz4-java@1.10.1
1.11.1

Open the chart page →

1,009
mod-quick-marcfolio-org0.1.351 of 1See more

mod-quick-marc folio-org 0.1.35

1 of the 1 container images this version deploys carry CVE-2026-59949.

Container imageDigestPackageFixed in
folioci/mod-quick-marc:latest4d70ebda4d00
lz4-java@1.10.1
1.11.1

Open the chart page →

63
mod-remote-storagefolio-org0.1.321 of 1See more

mod-remote-storage folio-org 0.1.32

1 of the 1 container images this version deploys carry CVE-2026-59949.

Container imageDigestPackageFixed in
folioci/mod-remote-storage:latest4f12177123dc
lz4-java@1.10.1
1.11.1

Open the chart page →

571
mod-searchfolio-org0.1.351 of 1See more

mod-search folio-org 0.1.35

1 of the 1 container images this version deploys carry CVE-2026-59949.

Container imageDigestPackageFixed in
folioci/mod-search:latest44d7ee9acdf6
lz4-java@1.10.1
1.11.1

Open the chart page →

1,531
mod-serials-managementfolio-org0.1.11 of 1See more

mod-serials-management folio-org 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-59949.

Container imageDigestPackageFixed in
folioci/mod-serials-management:latest571fa1ffe8c9
lz4-java@1.10.1
1.11.1

Open the chart page →

1,733
mod-service-interactionfolio-org0.1.61 of 1See more

mod-service-interaction folio-org 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-59949.

Container imageDigestPackageFixed in
folioci/mod-service-interaction:latestf53c327a48e8
lz4-java@1.10.1
1.11.1

Open the chart page →

1,733
mod-source-record-managerfolio-org0.1.371 of 1See more

mod-source-record-manager folio-org 0.1.37

1 of the 1 container images this version deploys carry CVE-2026-59949.

Container imageDigestPackageFixed in
folioci/mod-source-record-manager:latesta940caf026ee
lz4-java@1.10.2
1.11.1

Open the chart page →

58
mod-source-record-storagefolio-org0.1.371 of 1See more

mod-source-record-storage folio-org 0.1.37

1 of the 1 container images this version deploys carry CVE-2026-59949.

Container imageDigestPackageFixed in
folioci/mod-source-record-storage:latesta1434881eeb7
lz4-java@1.10.1
1.11.1

Open the chart page →

11
mod-usersfolio-org0.1.341 of 1See more

mod-users folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-59949.

Container imageDigestPackageFixed in
folioci/mod-users:latest6f60033321b0
lz4-java@1.10.2
1.11.1

Open the chart page →

430
druidhelmforgeVerified publisher1.3.61 of 4See more

druid helmforge 1.3.6

1 of the 4 container images this version deploys carry CVE-2026-59949.

Container imageDigestPackageFixed in
apache/druid:37.0.00116fb802786
lz4-java@1.10.2
1.11.1

Open the chart page →

8,541
metabasehelmforgeVerified publisher1.2.281 of 3See more

metabase helmforge 1.2.28

1 of the 3 container images this version deploys carry CVE-2026-59949.

Container imageDigestPackageFixed in
metabase/metabase:v0.63.16c6dd0c6a7861
lz4-java@1.10.4
1.11.1

Open the chart page →

1,793
ibm-events-operatoribm-helm6.0.0+20260126.110734.01 of 1See more

ibm-events-operator ibm-helm 6.0.0+20260126.110734.0

1 of the 1 container images this version deploys carry CVE-2026-59949.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:latest1af5dc3dcf8c
lz4-java@1.10.2
1.11.1

Open the chart page →

34
thehiveittrident-oss0.1.01 of 6See more

thehive ittrident-oss 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-59949.

Container imageDigestPackageFixed in
library/cassandra:4.0093ee8ee5eb2
lz4-java@1.10.1
1.11.1

Open the chart page →

6,122
kannikakannika0.18.01 of 3See more

kannika kannika 0.18.0

1 of the 3 container images this version deploys carry CVE-2026-59949.

Container imageDigestPackageFixed in
quay.io/kannika/kannika-api:0.18.0bcf9906d5a3c
lz4-java@1.10.2
1.11.1

Open the chart page →

717
sentinelopennms-helm-chartsVerified publisher0.4.01 of 2See more

sentinel opennms-helm-charts 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-59949.

Container imageDigestPackageFixed in
opennms/sentinel:36.0.288869082a14f
lz4-java@1.10.2
1.11.1

Open the chart page →

2,024
cp-cmfopenshift2.4.11 of 1See more

cp-cmf openshift 2.4.1

1 of the 1 container images this version deploys carry CVE-2026-59949.

Container imageDigestPackageFixed in
confluentinc/cp-cmf:2.4.1f466f8649aa8
lz4-java@1.10.1
1.11.1

Open the chart page →

179
trinoopstty0.2.121 of 1See more

trino opstty 0.2.12

1 of the 1 container images this version deploys carry CVE-2026-59949.

Container imageDigestPackageFixed in
trinodb/trino:4815b5e0a97f599
lz4-java@1.11.0
1.11.1

Open the chart page →

1,158
catalog-serverradar-baseVerified publisher0.9.31 of 1See more

catalog-server radar-base 0.9.3

1 of the 1 container images this version deploys carry CVE-2026-59949.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-schemas/radar-schemas-tools:0.8.16c442e8bfe6b4
lz4-java@1.10.1
1.11.1

Open the chart page →

2,418
radar-gatewayradar-baseVerified publisher1.9.01 of 2See more

radar-gateway radar-base 1.9.0

1 of the 2 container images this version deploys carry CVE-2026-59949.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-gateway/radar-gateway:0.9.4219d894aa7a6
lz4-java@1.10.1
1.11.1

Open the chart page →

2,284
hazelcaststakaterVerified publisher1.0.21 of 1See more

hazelcast stakater 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-59949.

Container imageDigestPackageFixed in
hazelcast/hazelcast:latestf086bf0ecb23
lz4-java@1.10.1
1.11.1

Open the chart page →

1,702
kafkatwomartensVerified publisher0.2.11 of 2See more

kafka twomartens 0.2.1

1 of the 2 container images this version deploys carry CVE-2026-59949.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:latest0ad069035863
lz4-java@1.10.2
1.11.1

Open the chart page →

1,551
elasticsearchwiremindVerified publisher8.19.01 of 1See more

elasticsearch wiremind 8.19.0

1 of the 1 container images this version deploys carry CVE-2026-59949.

Container imageDigestPackageFixed in
library/elasticsearch:8.19.1289729a95066a
lz4-java@1.10.1
1.11.1

Open the chart page →

2,191
metabasewiremindVerified publisher2.27.5-wiremind01 of 1See more

metabase wiremind 2.27.5-wiremind0

1 of the 1 container images this version deploys carry CVE-2026-59949.

Container imageDigestPackageFixed in
metabase/metabase:v0.61.1.x9491ed11c901
lz4-java@1.10.4
1.11.1

Open the chart page →

1,639
zipkinzipkinVerified publisher0.5.01 of 1See more

zipkin zipkin 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-59949.

Container imageDigestPackageFixed in
openzipkin/zipkin-slim:3.6.0a69e1057df36
lz4-java@1.10.1
1.11.1

Open the chart page →

1,159

Container images carrying it

87 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2:8.2.2-1-ubi98e01c0305844
lz4-java@1.10.1
1.11.1
7
apache/druid:37.0.00116fb802786
lz4-java@1.10.2
1.11.1
2
apache/kafka:4.3.177e3df905404
lz4-java@1.10.2
1.11.1
2
datagrok/grok_connect:latestf5876d3aebb8
lz4-java@1.10.1
1.11.1
2
graviteeio/apim-gateway:4.12.19-debian05fd67a93056
lz4-java@1.10.1
1.11.1
2
graviteeio/apim-management-api:4.12.19-debian27374522cd04
lz4-java@1.10.1
1.11.1
2
library/elasticsearch:8.19.1289729a95066a
lz4-java@1.10.1
1.11.1
2
metabase/metabase:v0.61.1.x9491ed11c901
lz4-java@1.10.4
1.11.1
2
ghcr.io/kafbat/kafka-ui:v1.5.07cda86a33344
lz4-java@1.10.1
1.11.1
2
public.ecr.aws/aktosecurity/akto-api-security-dashboard:1.69.2:latestb53a854bd7c1
lz4-java@1.10.1
1.11.1
2
quay.io/strimzi/operator:1.2.077f8fa8121a6
lz4-java@1.10.2
1.11.1
2
aktosecurity/akto-api-security-dashboard:latest3aeaee66bc66
lz4-java@1.10.1
1.11.1
1
aktosecurity/akto-threat-detection-backend:latest15ebb75b94dc
lz4-java@1.10.1
1.11.1
1
aktosecurity/akto-threat-detection-backend:1.15.7a6c1b933517f
lz4-java@1.10.1
1.11.1
1
aktosecurity/data-ingestion-service:1.5.35d4eab1c36b9
lz4-java@1.10.1
1.11.1
1
apache/polaris:lateste66366e783f1
lz4-java@1.10.1
1.11.1
1
confluentinc/cp-cmf:2.4.1f466f8649aa8
lz4-java@1.10.1
1.11.1
1
confluentinc/cp-kafka:latest0ad069035863
lz4-java@1.10.2
1.11.1
1
confluentinc/cp-schema-registry:latestf0cfd047a839
lz4-java@1.10.2
1.11.1
1
dbeaver/cloudbeaver:26.1.287ab86d00f8c
lz4-java@1.10.1
1.11.1
1
factorhouse/factor-platform:96.414728f9fd80f
lz4-java@1.10.1
1.11.1
1
factorhouse/kpow:96.4f9ce9b16b3a7
lz4-java@1.10.1
1.11.1
1
factorhouse/kpow-ce:96.466b08cc9e943
lz4-java@1.10.1
1.11.1
1
folioci/mod-agreements:latest29c3f233a498
lz4-java@1.10.1
1.11.1
1
folioci/mod-audit:latest88f40730ed45
lz4-java@1.10.1
1.11.1
1
folioci/mod-circulation:latest3eecd2ac2d8a
lz4-java@1.10.1
1.11.1
1
folioci/mod-circulation-storage:latest6bdddcafbc0f
lz4-java@1.10.1
1.11.1
1
folioci/mod-data-export-spring:latestf1d7caf4544b
lz4-java@1.10.1
1.11.1
1
folioci/mod-data-export-worker:latest1ad1811c9b37
lz4-java@1.10.1
1.11.1
1
folioci/mod-data-import:latestec2c3ebe3f2b
lz4-java@1.10.2
1.11.1
1
folioci/mod-entities-links:latest3e2412815c0f
lz4-java@1.10.1
1.11.1
1
folioci/mod-inn-reach:latestcc8584e43382
lz4-java@1.10.1
1.11.1
1
folioci/mod-inventory:latest53518ba29668
lz4-java@1.10.2
1.11.1
1
folioci/mod-inventory-storage:latestf92ff0a3ca40
lz4-java@1.10.1
1.11.1
1
folioci/mod-invoice:latest45b7b13e81e1
lz4-java@1.10.1
1.11.1
1
folioci/mod-invoice-storage:latest0bc720abcb78
lz4-java@1.10.1
1.11.1
1
folioci/mod-licenses:latestcfd6109bf477
lz4-java@1.10.1
1.11.1
1
folioci/mod-notes:latest998ac4782e0d
lz4-java@1.10.1
1.11.1
1
folioci/mod-oa:latestae3b069d4ba5
lz4-java@1.10.1
1.11.1
1
folioci/mod-orders:latestfc4528220fb8
lz4-java@1.10.1
1.11.1
1
folioci/mod-orders-storage:latestceeaacc3bf16
lz4-java@1.10.1
1.11.1
1
folioci/mod-organizations-storage:lateste46892405fde
lz4-java@1.10.1
1.11.1
1
folioci/mod-patron-blocks:latestde7318069a67
lz4-java@1.10.1
1.11.1
1
folioci/mod-pubsub:latest0a4fa4ad5d72
lz4-java@1.10.1
1.11.1
1
folioci/mod-quick-marc:latest4d70ebda4d00
lz4-java@1.10.1
1.11.1
1
folioci/mod-remote-storage:latest4f12177123dc
lz4-java@1.10.1
1.11.1
1
folioci/mod-search:latest44d7ee9acdf6
lz4-java@1.10.1
1.11.1
1
folioci/mod-serials-management:latest571fa1ffe8c9
lz4-java@1.10.1
1.11.1
1
folioci/mod-service-interaction:latestf53c327a48e8
lz4-java@1.10.1
1.11.1
1
folioci/mod-source-record-manager:latesta940caf026ee
lz4-java@1.10.2
1.11.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.