LZ4 Java Compression has Out-of-bounds memory operations which can cause DoS
High severity
GitHub Reviewed
Published
Nov 28, 2025
to the GitHub Advisory Database
•
Updated Dec 3, 2025
Description
Published by the National Vulnerability Database
Nov 28, 2025
Published to the GitHub Advisory Database
Nov 28, 2025
Reviewed
Dec 3, 2025
Last updated
Dec 3, 2025
Out-of-bounds memory operations in org.lz4:lz4-java 1.8.0 and earlier allow remote attackers to cause denial of service and read adjacent memory via untrusted compressed input.
This is fixed in a forked release: at.yawk.lz4:lz4-java version 1.8.1. The original project has been archived: https://github.com/lz4/lz4-java, and Sonatype has added a redirect from org.lz4:lz4-java:1.8.1 to the new group ID.
References