lz4-java is vulnerable to Use of Unmaintained Third Party Components
85
High Risk
This package is vulnerable to an information leakage issue as described in CVE-2025-66566. In addition, it is no longer maintained (latest update was 1.8.1), meaning security fixes and updates are unlikely to be provided. Users are encouraged to migrate to the actively maintained at.yawk.lz4:lz4-java package to reduce long-term security and maintenance risks.
You are affected if you are using this package.
lz4-java is vulnerable to Use of Unmaintained Third Party Components in versions 0.0.1 - 1.10.0.
Replace org.lz4:lz4-java by at.yawk.lz4:lz4-java version 1.10.1 or higher.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant