LZ4 bindings use a deprecated C API that is vulnerable to memory corruption, which could lead to arbitrary code execution if called with untrusted user input.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| github.com/cloudflare/golz4(Go) | 0 | 0.0.0-20140711154735-199f5f787806 | N/A |
CVSS Metrics