Insertion of Sensitive Information Into Sent Data in aircompressor - CVE-2025-67721

 

Insertion of Sensitive Information Into Sent Data in aircompressor - CVE-2025-67721

Published: April 28, 2026


Vulnerability identifier: #VU128324
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-67721
CWE-ID: CWE-201
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to insertion of sensitive information into sent data in the Java-based Snappy and LZ4 decompressor implementation when processing crafted compressed input. A remote attacker can send specially crafted compressed input to disclose sensitive information.

Exploitation requires the application to reuse the same decompression output buffer across calls without clearing it first.


Affected software

aircompressor
IBM Cloud Object Storage Systems

How to mitigate CVE-2025-67721

Install security update from vendor's website.

aircompressor - addressed in versions 2.0.3, 3.4
IBM Cloud Object Storage Systems - addressed in versions 3.20.0.43, 3.20.0.69

External References

Related Security Bulletins