PT-2025-51030 · Unknown · Aircompressor

CVE-2025-67721

·

Published

2025-12-12

·

Updated

2026-07-21

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Aircompressor versions 3.3 and below
Description Aircompressor is a Java library providing ports of Snappy, LZO, LZ4, and Zstandard compression algorithms. Incorrect handling of malformed data in the Java-based decompressor implementations for Snappy and LZ4 allows remote attackers to read previous buffer contents via crafted compressed input. With specific crafted compressed inputs, elements from the output buffer can appear in the uncompressed output, potentially exposing sensitive data. This is particularly relevant for applications that reuse the same output buffer for multiple decompression operations, such as web servers utilizing fixed-size buffers for performance.
Recommendations Update to version 3.4 or later.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-BO52019
CLEANSTART-2026-DO09088
CLEANSTART-2026-DT81884
CLEANSTART-2026-EG39405
CLEANSTART-2026-GX44743
CLEANSTART-2026-HQ78610
CLEANSTART-2026-RM01950
CLEANSTART-2026-VP53607
CVE-2025-67721
GHSA-VX9Q-RHV9-3JVG

Affected Products

Aircompressor