Skip to content

Switch from org.lz4:lz4-java to at.yawk.lz4:lz4-java due to CVE-2025-12183 & CVE-2025-66566. #1064

@mjschwaiger

Description

@mjschwaiger

Switch from org.lz4:lz4-java to at.yawk.lz4:lz4-java and update version >1.8.0 >=1.10.1 of lz4-java due to CVE-2025-12183 and CVE-2025-66566.

org.lz4:lz4-java library is discontinued and a fork at.yawk.lz4:lz4-java maintained by the community (@yawkat) was established.

Vulnerability CVE-2025-12183:

Also discussed in Apache projects:

See also pull request #992.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions