Skip to content

CVE-2026-59949 in at.yawk.lz4/lz4-java dependency #12090

Description

@amardeep2006

Tracer Version(s)

1.64.2

Java Version(s)

21

JVM Vendor

Eclipse Adoptium / Temurin

Bug Report

our secirity tool wiz has flagger datadog agent jar for https://advisories.gitlab.com/maven/at.yawk.lz4/lz4-java/CVE-2026-59949/ .

Please bump up the lz4-java to 1.11.1 in dependencies.

Expected Behavior

vulnerability scan must be clean.

Reproduction Code

No response

Activity

  1. self-assigned this
    on Jul 28, 2026
  2. added this to the 1.65.0 milestone on Jul 29, 2026
  3. vandonr commented on Jul 29, 2026

    @vandonr
    Contributor

    thanks for the headsup, this will be part of the next major release

  4. changed the title [-]CVE-2026-59949 in at.yawk.lz4/lz4-java dependencu+y[/-] [+]CVE-2026-59949 in at.yawk.lz4/lz4-java dependency[/+] on Jul 29, 2026
  5. dd-octo-sts commented on Aug 4, 2026

    @dd-octo-sts
    Contributor

    🤖 This issue has been addressed in the latest release. Check full details in the Release Notes.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions