Intel

AIKIDO-2026-10115

lz4-java is vulnerable to Use of Unmaintained Third Party Components

Use of Unmaintained Third Party ComponentsCVE-2025-66566 Published Feb 5, 2026

85

High Risk

This Affects:

JAVAlz4-java
0.0.1 - 1.10.0
Fixed in 1.10.1
Are you affected? Scan for Free

TL;DR

This package is vulnerable to an information leakage issue as described in CVE-2025-66566. In addition, it is no longer maintained (latest update was 1.8.1), meaning security fixes and updates are unlikely to be provided. Users are encouraged to migrate to the actively maintained at.yawk.lz4:lz4-java package to reduce long-term security and maintenance risks.

Who does this affect?

You are affected if you are using this package.

Background info

lz4-java is vulnerable to Use of Unmaintained Third Party Components in versions 0.0.1 - 1.10.0.

How to fix this

Replace org.lz4:lz4-java by at.yawk.lz4:lz4-java version 1.10.1 or higher.