3 Total advisories
3 Vulnerabilities
0 Malware
Dependency scanning
Check whether at.yawk.lz4:lz4-java is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
MEDIUM 6.5
CVE-2026-59949
LZ4 Java: Native XXHash implementations can crash the JVM when passed invalid byte array ranges
UNKNOWN
CVE-2025-66566
yawkat LZ4 Java has a possible information leak in Java safe decompressor
UNKNOWN
CVE-2025-12183
LZ4 Java Compression has Out-of-bounds memory operations which can cause DoS
Browse more Maven advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes