Skip to content

[3.0.x] Bump to lz4-java 1.10.1 to fix CVE-2025-66566 #13684

Merged
mkurz merged 1 commit into
playframework:3.0.xfrom
mkurz:lz4-java-1.10.1
Dec 7, 2025
Merged

[3.0.x] Bump to lz4-java 1.10.1 to fix CVE-2025-66566 #13684
mkurz merged 1 commit into
playframework:3.0.xfrom
mkurz:lz4-java-1.10.1

Conversation

@mkurz
Copy link
Copy Markdown
Member

@mkurz mkurz commented Dec 7, 2025

This one is different than cve-2025-12183 in just merged #13682
Details: GHSA-cmp6-m4wj-q63q

@mkurz mkurz merged commit e986b17 into playframework:3.0.x Dec 7, 2025
25 checks passed
@mkurz mkurz deleted the lz4-java-1.10.1 branch December 7, 2025 00:37
@mkurz mkurz added this to the 3.0.10 milestone Dec 22, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant