Vulnerabilities

1 via 2 paths

Dependencies

116

Source

GitHub

Commit

25eba27a

Find, fix and prevent vulnerabilities in your code.

Issue type
  • 1
  • 2
Severity
  • 1
  • 2
Status
  • 3
  • 0
  • 0

high severity

Insertion of Sensitive Information Into Sent Data

  • Vulnerable module: org.lz4:lz4-java
  • Introduced through: org.lz4:lz4-java@1.8.1 and org.apache.kafka:kafka-clients@4.1.1

Detailed paths

  • Introduced through: laserdisc-io/tamer@laserdisc-io/tamer#25eba27ae9fbb5a18b7846717a5feb344a0e3e1b org.lz4:lz4-java@1.8.1
  • Introduced through: laserdisc-io/tamer@laserdisc-io/tamer#25eba27ae9fbb5a18b7846717a5feb344a0e3e1b org.apache.kafka:kafka-clients@4.1.1 org.lz4:lz4-java@1.8.1

Overview

org.lz4:lz4-java is a Java port of the LZ4 compression algorithm and the xxHash hashing algorithm.

Affected versions of this package are vulnerable to Insertion of Sensitive Information Into Sent Data in the decompression process when the output buffer is reused without being cleared. An attacker can access sensitive information from previous buffer contents by providing crafted compressed input.

Note:

  • JNI implementations are not vulnerable.
  • LZ4Factory.safeInstance(), LZ4Factory.unsafeInstance(), and LZ4Factory.fastestJavaInstance() are all vulnerable.
  • nativeInstance().fastDecompressor() is vulnerable but nativeInstance().safeDecompressor() is not.
  • This vulnerability is distinct from the one described in CVE-2025-12183, and was discovered during follow-up research.

Workaround

This vulnerability can be mitigated by zeroing the output buffer before passing it to the decompression function.

Remediation

There is no fixed version for org.lz4:lz4-java.

References

medium severity

Dual license: EPL-1.0, LGPL-2.1

  • Module: ch.qos.logback:logback-classic
  • Introduced through: ch.qos.logback:logback-classic@1.5.25

Detailed paths

  • Introduced through: laserdisc-io/tamer@laserdisc-io/tamer#25eba27ae9fbb5a18b7846717a5feb344a0e3e1b ch.qos.logback:logback-classic@1.5.25

Dual license: EPL-1.0, LGPL-2.1

medium severity

Dual license: EPL-1.0, LGPL-2.1

  • Module: ch.qos.logback:logback-core
  • Introduced through: ch.qos.logback:logback-classic@1.5.25

Detailed paths

  • Introduced through: laserdisc-io/tamer@laserdisc-io/tamer#25eba27ae9fbb5a18b7846717a5feb344a0e3e1b ch.qos.logback:logback-classic@1.5.25 ch.qos.logback:logback-core@1.5.25

Dual license: EPL-1.0, LGPL-2.1