CVE-2025-12183

unknown
Published 2025-11-28 · Modified 2026-03-06
CVSS v3
VIR risk

Description

LZ4 Java Compression has Out-of-bounds memory operations which can cause DoS

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.

OS impact

OSVersionStatusFixed in
debian debianbookwormaffected
debian debianbullseyeaffected
debian debianforkyaffected
debian debiansidaffected
debian debiantrixieaffected

Package impact

EcosystemPackageVulnerableFixed
java Mavenat.yawk.lz4:lz4-java<1.8.11.8.1
java Mavenorg.lz4:lz4-java<1.8.11.8.1
java Mavenorg.lz4:lz4-pure-java<=1.8.0
java Mavennet.jpountz.lz4:lz4<=1.3.0

References

💬 Discuss CVE-2025-12183 on VIR Community →

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.