at.yawk.lz4:lz4-java
Maven8 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting at.yawk.lz4:lz4-javapage 1 of 1
- CVE-2025-12183HIGHCVSS 8.8EG 8.8fixed in 1.8.12025-11-28
Out-of-bounds memory operations in org.lz4:lz4-java 1.8.0 and earlier allow remote attackers to cause denial of service and read adjacent memory via untrusted compressed input.
- CVE-2025-66566HIGHCVSS 8.2EG 8.2fixed in 1.10.12025-12-05
vulnerable: 1.10.0, 1.8.1, 1.9.0
yawkat LZ4 Java provides LZ4 compression for Java. Insufficient clearing of the output buffer in Java-based decompressor implementations in lz4-java 1.10.0 and earlier allows remote attackers to read previous buffer contents via crafted co…
- CVE-2026-106449LOWCVSS 3.7EG 3.7fixed in 1.11.42026-10-06
vulnerable: 1.10.0 ... 1.9.0 (11 versions)
yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.4, net.jpountz.lz4.LZ4BlockInputStream configured with stopOnEmptyBlock set to false handles each well-formed empty LZ4Block by recursively calling refill(), allowing a long …
- CVE-2026-106450MEDIUMCVSS 5.3EG 5.3fixed in 1.11.42026-10-06
vulnerable: 1.10.0 ... 1.9.0 (11 versions)
yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.4, net.jpountz.lz4.LZ4FrameInputStream readHeader() allocates two new 4 MiB block buffers whenever a maximum-block-size frame header is read, and the default concatenated-fra…
- CVE-2026-106451HIGHCVSS 7.3EG 7.3fixed in 1.11.42026-10-06
vulnerable: 1.10.0 ... 1.9.0 (11 versions)
yawkat LZ4 Java provides LZ4 compression for Java. From 1.7.0 until 1.11.4, net.jpountz.util.Native.load() uses File.createTempFile to create an exclusive temporary .lck file but derives the native-library path by removing the suffix, then…
- CVE-2026-106452MEDIUMCVSS 5.3EG 5.3fixed in 1.11.22026-10-06
vulnerable: 1.10.0 ... 1.9.0 (9 versions)
yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.2, net.jpountz.lz4.LZ4BlockInputStream refill() validates that the compressedLen field in a legacy LZ4Block header is nonnegative but allocates a compressed-input buffer of t…
- CVE-2026-106453MEDIUMCVSS 5.3EG 5.3fixed in 1.11.22026-10-06
vulnerable: 1.10.0 ... 1.9.0 (9 versions)
yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.2, LZ4DecompressorWithLength uses getDecompressedLength to trust the four-byte decompressed-length header before validating the compressed input, allowing a five-byte attacke…
- CVE-2026-59949MEDIUMCVSS 6.5EG 6.5fixed in 1.11.12026-07-24
vulnerable: 1.10.0 ... 1.9.0 (8 versions)
yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JNI-backed XXHash implementations fail to validate the byte array object and the off and len arguments in XXHashFactory.nativeInstance().hash32().hash(), XXHashFactory.nat…
Check whether at.yawk.lz4:lz4-java is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for at.yawk.lz4:lz4-java CVEs against the assets you own.
Book a Demo →