Skip to content

[CVE-2025-12183] HIGH: lz4-java 1.8.0 - Out-of-bounds memory and information disclosure #83

@nthmost-orkes

Description

@nthmost-orkes

Vulnerability Report

Field Value
CVEs CVE-2025-12183, CVE-2025-66566
Severity HIGH (2 CVEs)
Library org.lz4:lz4-java
Source workers.jar
Installed Version 1.8.0
Fixed Version 1.8.1 (CVE-2025-12183); unknown (CVE-2025-66566)

Summary

Two vulnerabilities in lz4-java:

  1. CVE-2025-12183 - Out-of-bounds memory operations lead to denial of service and information disclosure
  2. CVE-2025-66566 - Information Disclosure via Insufficient Output Buffer Clearing

References


Filed from container vulnerability scan of workers.jar

Metadata

Metadata

Assignees

No one assigned

    Labels

    securitySecurity-related issuesvulnerabilityDependency vulnerability

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions