CVE-2025-12183 | Sonatype Security Advisory

CVE-2025-12183

Summary

Various lz4-java compression and decompression implementations do not guard against out-of-bounds memory access. Untrusted input may lead to denial of service and information disclosure.

Vulnerable Maven coordinates:

Severity rating & weakness enumeration

Rating: High - 8.8
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N CWE-125: Out-of-bounds Read

Technical Description

lz4-java provides a matrix of compression and decompression algorithms:

Each of these variants has:

The JNI "fast" decompressor is based on the LZ4_decompress_fast API of the lz4 C library. This function is deprecated because it lacks bounds checks and is insecure on untrusted input. Other JNI-based APIs (the safe decompressor and the compressors) are not vulnerable.

All Java-based implementations lack sufficient bounds checks. For the sun.misc.Unsafe-based implementations, this can lead to denial of service and information disclosure. For the normal Java implementations, this only leads to ArrayIndexOutOfBoundsExceptions and is not a vulnerability.

Workaround

The vulnerability can be resolved without patching:

With the 1.8.1 patch applied, these workarounds are not necessary. It is still recommended to move from fastDecompressor to safeDecompressor to mitigate the performance impact of the fix, however.

Patch

Because the maintainer of the official lz4-java library is unavailable, the lz4 organization has decided to discontinue the project.

A community-maintained fork of lz4-java is available at https://github.com/yawkat/lz4-java. Two new versions have been released.

at.yawk.lz4:lz4-java:1.8.1 implements the workarounds listed above. The JNI-based fast decompressor is replaced with the safe Java implementation. All sun.misc.Unsafe-based compressors and decompressors are replaced with their safe counterparts. New unsafeInsecureInstance and nativeInsecureInstance factory methods were added for the insecure implementations for applications that operate on trusted input only. This version is directly based on 1.8.0 and only includes the minimum changes necessary to fix the vulnerability.

at.yawk.lz4:lz4-java:1.9.0 adds a reworked build system, updates to the underlying lz4 library (not security-related), and various fixes for the Java implementations. The changes from 1.8.1 remain. The Unsafe-based implementation may be made available by default again in a future release, once there is confidence in the security of the patched implementation.

org.lz4:lz4-java:1.8.1 is a relocation pom pointing to at.yawk.lz4:lz4-java:1.8.1, provided by Sonatype. Users that upgrade to the former coordinates will get the latter artifact, and a warning to update their maven coordinates. Future releases (including 1.9.0) will only be published under the at.yawk.lz4 group ID.

Credits

Latest CVE Disclosures

CVE-2025-13158 [CVE-2025-1945

Pickescan - Bypass Malicious Pickle Detection inside PyTorch Models via ZIP File Flag Bits](/content/security-advisories/cve-2025-1945/index.html) [CVE-2025-1944

Picklescan - Security Scanning Bypass via Non-Standard File Extensions](/content/security-advisories/cve-2025-1944/index.html) [CVE-2025-1889

Picklescan - Security Scanning Bypass via Non-Standard File Extensions](/content/security-advisories/cve-2025-1889/index.html) [CVE-2025-1716

Picklescan - Security Scanning Bypass Via 'Pip Main'](/content/security-advisories/cve-2025-1716/index.html)