SB2026042867 - Insertion of Sensitive Information Into Sent Data in aircompressor
Published: April 28, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Insertion of Sensitive Information Into Sent Data (CVE-ID: CVE-2025-67721)
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to insertion of sensitive information into sent data in the Java-based Snappy and LZ4 decompressor implementation when processing crafted compressed input. A remote attacker can send specially crafted compressed input to disclose sensitive information.
Exploitation requires the application to reuse the same decompression output buffer across calls without clearing it first.
Remediation
Install update from vendor's website.