Known vulnerabilities in lz4-java
Vendor:
jpountz (Adrien Grand)
Software:
lz4-java
Software CPE:
cpe:2.3:a:jpountz:lz4-java:*:*:*:*:*:*:*:*
Website:
https://github.com/jpountz/
Total vulnerabilities:
6
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.8
Breakdown by Severity Chart
Vulnerabilities (6)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU141232 - Uncontrolled Memory Allocation |
CWE-789 | Medium | 1.11.2 | 07.08.2026 |
SB2026080725 |
||
| #VU141231 - Uncontrolled Memory Allocation |
CWE-789 | Medium | 1.11.2 | 07.08.2026 |
SB2026080725 |
||
| #VU137031 - NULL Pointer Dereference CVE-2026-59949 |
CWE-476 | Low | 1.11.1 | 07.07.2026 |
SB2026070772 |
||
| #VU137032 - Out-of-bounds read |
CWE-125 | Low | 1.11.1 | 07.07.2026 |
SB2026070772 |
||
| #VU121007 - Exposure of sensitive information to an unauthorized actor CVE-2025-66566 |
CWE-200 | Medium | 1.10.1 | 07.01.2026 |
SB2026010702 SB2026010705 SB2026010706 and 28 more |
||
| #VU121006 - Out-of-bounds read CVE-2025-12183 |
CWE-125 | Medium | 1.8.1 | 07.01.2026 |
SB2026010701 SB2026010705 SB2026010706 and 14 more |