CVE-2026-106451 with a CVSS score of 7.3 is a vulnerability affecting lz4-java versions <= 1.11.3 affecting lz4-java versions >= 1.7.0, <= 1.8.1 in lz4-java that allows an attacker to load arbitrary code by exploiting a shared temporary directory, host settings permitting, and winning a race condition. The flaw type is a native library extraction issue, where the bundled JNI library can be replaced by another local user who can write to the same temporary directory as the victim process. This allows exploitation by a local user who can write to the same temporary directory, requiring a shared temporary directory, host settings that permit it, and winning a race condition. The business impact is significant, as an attacker may be able to execute code as the victim, potentially leading to arbitrary code execution.
We recommend you to update lz4-java to version 1.11.4.[/subscribe_to_unlock_form]
CVE-2026-106451 with a CVSS score of 7.3 is a vulnerability affecting lz4-java versions <= 1.11.3 affecting lz4-java versions >= 1.7.0, <= 1.8.1 in lz4-java that allows an attacker to load arbitrary code by exploiting a shared temporary directory, host settings permitting, and winning a race condition. The flaw type is a native library extraction issue, where the bundled JNI library can be replaced by another local user who can write to the same temporary directory as the victim process. This allows exploitation by a local user who can write to the same temporary directory, requiring a shared temporary directory, host settings that permit it, and winning a race condition. The business impact is significant, as an attacker may be able to execute code as the victim, potentially leading to arbitrary code execution.
We recommend you to update lz4-java to version 1.11.4.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]