Skip to content

Conversation

@alaudaa-renovate
Copy link

@alaudaa-renovate alaudaa-renovate bot commented Dec 4, 2025

This PR contains the following updates:

Package Change Age Confidence
org.lz4:lz4-java 1.8.0 -> 1.8.1 age confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


LZ4 Java Compression has Out-of-bounds memory operations which can cause DoS

CVE-2025-12183 / GHSA-vqf4-7m7x-wgfc

More information

Details

Out-of-bounds memory operations in org.lz4:lz4-java 1.8.0 and earlier allow remote attackers to cause denial of service and read adjacent memory via untrusted compressed input.

This is fixed in a forked release: at.yawk.lz4:lz4-java version 1.8.1. The original project has been archived: https://github.com/lz4/lz4-java, and Sonatype has added a redirect from org.lz4:lz4-java:1.8.1 to the new group ID.

Severity

  • CVSS Score: Unknown
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Configuration

📅 Schedule: Branch creation - "" in timezone Asia/Shanghai, Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@alaudaa-renovate alaudaa-renovate bot changed the title fix(deps): update dependency org.lz4:lz4-java to v1.8.1 [security] fix(deps): update dependency org.lz4:lz4-java to v1.8.1 [security] - abandoned Dec 8, 2025
@alaudaa-renovate
Copy link
Author

Autoclosing Skipped

This PR has been flagged for autoclosing. However, it is being skipped due to the branch being already modified. Please close/delete it manually or report a bug if you think this is in error.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant