Information disclosure in lz4-java - CVE-2025-66566

 

Information disclosure in lz4-java - CVE-2025-66566

Published: January 7, 2026


Vulnerability identifier: #VU121007
CSH Severity: Medium
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-66566
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to the application insufficiently clears the output buffer in Java-based decompressor implementations. In applications where the output buffer is reused without being cleared, this may lead to disclosure of sensitive data.

Note, JNI-based implementations are not affected.


Affected software

lz4-java
clickhouse-java
Enterprise Build of Quarkus
Log Analysis
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Cloud Application Performance Management (APM)
IBM Maximo Application Suite - Manage Component
Logstash
Infrastructure Technology
Red Hat build of Quarkus
IBM Global High Availability Mailbox
App Connect Enterprise Certified Container
Elasticsearch
Oracle Banking Corporate Lending Process Management
Oracle Banking Origination
Oracle Banking Branch
Oracle Banking Cash Management
Stream Analytics
IBM Qradar SIEM
Communications Service Catalog and Design
IBM InfoSphere Information Server
Oracle Communications BRM - Elastic Charging Engine
Oracle Essbase
IBM Disconnected Log Collector
Red Hat Camel for Spring Boot
jmc (Red Hat package)

How to mitigate CVE-2025-66566

Install updates from vendor's website.

lz4-java - update to 1.10.1
clickhouse-java - update to 0.9.6
Log Analysis - update to 1.3.8.3 IF001
Enterprise Build of Quarkus - update to 3.27.1.SP1
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.1
Elasticsearch - addressed in versions 8.19.10, 9.1.10, 9.2.4
IBM Qradar SIEM - update to 7.5.0 Update Pack 15 IF05
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.19
IBM Maximo Application Suite - Manage Component - addressed in versions 8.6.34, 8.7.28, 9.0.21, 9.1.8
Logstash - addressed in versions 8.19.10, 9.1.10, 9.2.4
IBM InfoSphere Information Server - update to 11.7.1.6 Service pack 1
IBM Disconnected Log Collector - update to 2.0.1
Red Hat build of Quarkus - addressed in versions 3.20.4.SP1, 3.27.1.SP1
Red Hat Camel for Spring Boot - addressed in versions 4.10, 4.14, 4.14.2
IBM Global High Availability Mailbox - addressed in versions 6.2.0.6 6212, 6.2.0.6 6221
jmc (Red Hat package) - addressed in versions 8.2.0-18.el9_6.2, 8.2.0-18.el9_7.2, 8.2.0-19.el9_8.2
App Connect Enterprise Certified Container - addressed in versions 12.0.23, 13.1.0

External References

Related Security Bulletins