HIGHMaven

aircompressor Snappy and LZ4 Java-based decompressor implementation can leak information from reused output buffer

aircompressor Snappy and LZ4 Java-based decompressor implementation can leak information from reused output buffer

CVE-2025-67721Published 9 months agoUpdated 5 days agoSource: OSV

Affected packages

  • io.airlift:aircompressorbefore 2.0.3
  • io.airlift:aircompressor-v3before 3.4

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
EPSS percentile

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.

aircompressor Snappy and LZ4 Java-based decompressor implementation can leak information from reused output buffer | HackTribune