Intel

AIKIDO-2026-10116

lz4 is vulnerable to Use of Unmaintained Third Party Components

Use of Unmaintained Third Party ComponentsCVE-2025-66566 Published Feb 5, 2026

85

High Risk

This Affects:

JAVAlz4
0.0.1 - 1.10.0
Fixed in 1.10.1
Are you affected? Scan for Free

TL;DR

This package is vulnerable to an information leakage issue as described in CVE-2025-66566. In addition, it is no longer maintained (latest update was 1.8.1), meaning security fixes and updates are unlikely to be provided. Users are encouraged to migrate to the actively maintained at.yawk.lz4:lz4-java package to reduce long-term security and maintenance risks.

Who does this affect?

You are affected if you are using this package.

Background info

lz4 is vulnerable to Use of Unmaintained Third Party Components in versions 0.0.1 - 1.10.0.

How to fix this

Replace net.jpountz.lz4:lz4 by at.yawk.lz4:lz4-java version 1.10.1 or higher.