CVE-2014-125026: Cloudflare GOLZ4

Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.

LZ4 bindings use a deprecated C API that is vulnerable to memory corruption, which could lead to arbitrary code execution if called with untrusted user input.

Affected products

  • Cloudflare GOLZ4: before 2014-07-11 (fixed in 2014-07-11)

Published 2022-12-27. Last modified 2026-06-17.