Vulnerability CVE-2014-125026


Published: 2022-12-27

Description:
LZ4 bindings use a deprecated C API that is vulnerable to memory corruption, which could lead to arbitrary code execution if called with untrusted user input.

 References:
https://github.com/cloudflare/golz4/issues/5
https://pkg.go.dev/vuln/GO-2020-0022
https://github.com/cloudflare/golz4/commit/199f5f7878062ca17a98e079f2dbe1205e2ed898

Copyright 2026, cxsecurity.com

 

Back to Top