Switch from org.lz4:lz4-java to at.yawk.lz4:lz4-java and update version >1.8.0 >=1.10.1 of lz4-java due to CVE-2025-12183 and CVE-2025-66566.
org.lz4:lz4-java library is discontinued and a fork at.yawk.lz4:lz4-java maintained by the community (@yawkat) was established.
Vulnerability CVE-2025-12183:
Also discussed in Apache projects:
See also pull request #992.
Switch from
org.lz4:lz4-javatoat.yawk.lz4:lz4-javaand update version>1.8.0>=1.10.1oflz4-javadue to CVE-2025-12183 and CVE-2025-66566.org.lz4:lz4-javalibrary is discontinued and a forkat.yawk.lz4:lz4-javamaintained by the community (@yawkat) was established.lz4-javarepo seems lack of maintainers lz4/lz4#1346Vulnerability CVE-2025-12183:
Also discussed in Apache projects:
See also pull request #992.