What is CVE-2026-59949?
CVE-2026-59949 is a vulnerability in the JNI-backed XXHash implementation of the yawkat LZ4 Java library. Versions prior to 1.11.1 fail to validate the byte array object, offset, and length arguments in certain methods, posing a security risk. Upgrading to version 1.11.1 or later is recommended.
Azərbaycanca: CVE-2026-59949, yawkat LZ4 Java kitabxanasında JNI əsaslı XXHash tətbiqində tapılan bir zəiflikdir. 1.11.1 versiyasından əvvəlki versiyalarda, təqdim olunan byte array, ofset (off) və uzunluq (len) arqumentlərinin düzgün yoxlanılmaması təhlükəsizlik riski yaradır. Təsirə məruz qalmamaq üçün kitabxananı ən azı 1.11.1 versiyasına yeniləmək tövsiyə olunur.
FAQ2
In which component of the yawkat LZ4 Java library is CVE-2026-59949 found?
This vulnerability is found in the JNI-backed XXHash implementation.
How can one protect against CVE-2026-59949?
Upgrading the library to version 1.11.1 or later avoids being affected.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.