Security: yawkat/lz4-java
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
Native library extraction to a shared temporary directory is vulnerable to file replacement by another local userGHSA-mcr4-qmvw-px4g published
Sep 25, 2026 by yawkatLow -
LZ4BlockInputStream with stopOnEmptyBlock=false recurses once per empty block, causing StackOverflowErrorGHSA-343h-94h5-c4wr published
Sep 25, 2026 by yawkatLow -
LZ4FrameInputStream reallocates block buffers for every frame, allowing CPU and GC amplification from small inputsGHSA-gm45-99xc-r7wv published
Sep 25, 2026 by yawkatModerate -
LZ4BlockInputStream allocates an unvalidated compressed length from the stream headerGHSA-4v53-57pg-c464 published
Aug 6, 2026 by yawkatModerate -
LZ4DecompressorWithLength allocates the unvalidated size from the 4-byte length header, so a 5-byte input triggers a 1 GiB allocation and OutOfMemoryErrorGHSA-6cx8-rjf8-pr8g published
Aug 6, 2026 by yawkatModerate -
Native XXHash implementations can crash the JVM when passed invalid byte array rangesGHSA-xx22-p4ch-683r published
Jul 6, 2026 by yawkatModerate -
Java-based decompressor implementations can leak information from uninitialized output bufferGHSA-cmp6-m4wj-q63q published
Dec 5, 2025 by yawkatHigh
Learn more about advisories related to yawkat/lz4-java in the GitHub Advisory Database