CVE-2025-12183

High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Out-of-bounds memory operations in org.lz4:lz4-java 1.8.0 and earlier allow remote attackers to cause denial of service and read adjacent memory via untrusted compressed input.

Published 2025-11-28. Last modified 2026-06-17.