CVE-2025-12183: org.lz4:lz4-java - Out-of-Bounds Memory Access
Published Nov 28, 2025
·Updated
Out-of-bounds memory operations in org.lz4:lz4-java 1.8.0 and earlier allow remote attackers to cause denial of service and read adjacent memory via untrusted compressed input.
Affected Software
7 affected componentsFixes available
org.lz4 lz4-java<1.8.0
maven/net.jpountz.lz4:lz4<=1.3.0
maven/org.lz4:lz4-pure-java<=1.8.0
maven/org.lz4:lz4-java<1.8.1
1.8.1
maven/at.yawk.lz4:lz4-java<1.8.1
1.8.1
IBM Cloud APM, Base Private<=8.1.4
IBM Cloud APM, Advanced Private<=8.1.4
Event History
Nov 28, 2025
CVE Published
via MITRE·03:52 PM
Data Sourced
via MITRE·03:52 PM
DescriptionWeakness
Data Sourced
via Red Hat·04:01 PM
DescriptionSeverityAffected Software
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·06:30 PM
Data Sourced
via GitHub·06:30 PM
DescriptionWeaknessAffected Software
May 21, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-12183?
CVE-2025-12183 has been classified with a high severity due to its potential to cause denial of service and memory read vulnerabilities.
2
How do I fix CVE-2025-12183?
To mitigate CVE-2025-12183, upgrade to lz4-java version 1.8.1 or later.
3
What causes CVE-2025-12183?
CVE-2025-12183 is caused by out-of-bounds memory operations in lz4-java 1.8.0 and earlier when handling untrusted compressed input.
4
What potential impacts does CVE-2025-12183 have?
The impacts of CVE-2025-12183 include remote denial of service and possible exposure of adjacent memory.
5
Is CVE-2025-12183 exploitable remotely?
Yes, CVE-2025-12183 can be exploited remotely through untrusted input sent to the vulnerable lz4-java implementation.