Search CVE reports


Toggle filters

1 – 10 of 14 results


CVE-2026-106453

Medium priority
Needs evaluation

(yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.2, LZ ...)

1 affected package

lz4-java

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lz4-java Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-106452

Medium priority
Needs evaluation

(yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.2, ne ...)

1 affected package

lz4-java

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lz4-java Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-106451

Medium priority
Needs evaluation

(yawkat LZ4 Java provides LZ4 compression for Java. From 1.7.0 until 1. ...)

1 affected package

lz4-java

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lz4-java Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-106450

Medium priority
Needs evaluation

(yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.4, ne ...)

1 affected package

lz4-java

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lz4-java Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-106449

Medium priority
Needs evaluation

(yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.4, ne ...)

1 affected package

lz4-java

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lz4-java Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-59949

Medium priority
Needs evaluation

yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JNI-backed XXHash implementations fail to validate the byte array object and the off and len arguments...

1 affected package

lz4-java

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lz4-java Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-32829

Medium priority
Needs evaluation

lz4_flex is a pure Rust implementation of LZ4 compression/decompression. In versions 0.11.5 and below, and 0.12.0, decompressing invalid LZ4 data can leak sensitive information from uninitialized memory or from...

1 affected package

rust-lz4-flex

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rust-lz4-flex Needs evaluation Needs evaluation Not in release — —
Show less packages

CVE-2025-66566

Medium priority
Vulnerable

yawkat LZ4 Java provides LZ4 compression for Java. Insufficient clearing of the output buffer in Java-based decompressor implementations in lz4-java 1.10.0 and earlier allows remote attackers to read previous buffer contents via...

1 affected package

lz4-java

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lz4-java Vulnerable Vulnerable Vulnerable Vulnerable —
Show less packages

CVE-2025-12183

Medium priority
Needs evaluation

Out-of-bounds memory operations in org.lz4:lz4-java 1.8.0 and earlier allow remote attackers to cause denial of service and read adjacent memory via untrusted compressed input.

1 affected package

lz4-java

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lz4-java Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2025-62813

Medium priority
Not affected

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

1 affected package

lz4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lz4 — Not affected Not affected Not affected Not affected
Show less packages