HIGHMaven →
aircompressor Snappy and LZ4 Java-based decompressor implementation can leak information from reused output buffer
aircompressor Snappy and LZ4 Java-based decompressor implementation can leak information from reused output buffer
Affected packages
- io.airlift:aircompressor— before 2.0.3
- io.airlift:aircompressor-v3— before 3.4
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://github.com/airlift/aircompressor/security/advisories/GHSA-vx9q-rhv9-3jvg
- https://nvd.nist.gov/vuln/detail/CVE-2025-67721
- https://github.com/airlift/aircompressor/pull/309
- https://github.com/airlift/aircompressor/commit/f2b489b398779b40c1ee29ddb11d7edef54ddc15
- https://github.com/airlift/aircompressor/commit/ff12c4d5757c9d6d1de3d39a10402f1f84f9b765
- https://github.com/airlift/aircompressor
- https://github.com/airlift/aircompressor/releases/tag/2.0.3
Structured record: https://osv.dev/vulnerability/GHSA-vx9q-rhv9-3jvg
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta