CVE-2026-106451
Last modified
CVE-2026-106451 is a high-severity vulnerability rated 7.3/10 on the CVSS scale. yawkat LZ4 Java provides LZ4 compression for Java. From 1.7.0 until 1.11.4, net.jpountz.util.Native.load() uses File.createTempFile to create an exclusive temporary .lck file but derives the native-library path by removing the suffix, then FileOutputStream opens that predictable path without exclusive creation, allowing another local user with access to the same shared temporary directory to create or replace the library file before System.load() uses it. EPSS estimates a 0.08% chance of exploitation in the next 30 days.
Description
yawkat LZ4 Java provides LZ4 compression for Java. From 1.7.0 until 1.11.4, net.jpountz.util.Native.load() uses File.createTempFile to create an exclusive temporary .lck file but derives the native-library path by removing the suffix, then FileOutputStream opens that predictable path without exclusive creation, allowing another local user with access to the same shared temporary directory to create or replace the library file before System.load() uses it. Successful exploitation depends on shared-directory permissions, host protections, and winning the race, and can execute native code as the victim; hardened systems may instead cause library loading to fail and fall back to Java implementations. Configurations using a system library, a private java.io.tmpdir, or Java-only implementations are not affected. This issue is fixed in version 1.11.4.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| yawkat | lz4-java | < 1.11.4 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-106451?
How severe is CVE-2026-106451?
How do I fix CVE-2026-106451?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-106446Handlebars provides the power necessary to let users build s…9.8
- CVE-2026-106447StableLib is a stable library of useful TypeScript and JavaS…8.7
- CVE-2026-106448StableLib is a stable library of useful TypeScript and JavaS…8.9
- CVE-2026-106449yawkat LZ4 Java provides LZ4 compression for Java. Prior to …3.7
- CVE-2026-10645The Zephyr ext2 filesystem driver (subsys/fs/ext2) trusted t…5.5
- CVE-2026-106450yawkat LZ4 Java provides LZ4 compression for Java. Prior to …5.3
- CVE-2026-106452yawkat LZ4 Java provides LZ4 compression for Java. Prior to …5.3
- CVE-2026-106453yawkat LZ4 Java provides LZ4 compression for Java. Prior to …5.3
- CVE-2026-106454Twisted is an event-based framework for internet application…4.3
- CVE-2026-106455Backstage is an open framework for building developer portal…7.7
- CVE-2026-106456Backstage is an open framework for building developer portal…4.8
- CVE-2026-106457Backstage is an open framework for building developer portal…6.8
Are you affected by CVE-2026-106451?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
