Home
HIGH: 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:NDefault status
unaffected
1.0.0 (semver)
affected
Default status
unaffected
1.0.0 (semver)
affected
Default status
unaffected
1.0.0 (semver)
affected
Description
Out-of-bounds memory operations in org.lz4:lz4-java 1.8.0 and earlier allow remote attackers to cause denial of service and read adjacent memory via untrusted compressed input.
Problem types
Product status
1.0.0 (semver)
1.0.0 (semver)
1.0.0 (semver)
Credits
Jonas Konrad (Oracle corp.)
Marcono1234
References
www.openwall.com/lists/oss-security/2025/12/01/5
sites.google.com/sonatype.com/vulnerabilities/cve-2025-12183
github.com/yawkat/lz4-java/releases/tag/v1.8.1