cargo package reportIs lz4-compress safe?
1 known vulnerability.
// reach0 direct dependencies
none carry a known advisory
0 packages depend on it
an advisory here reaches each of them
// ai model usageTracked for PyPI packages. HuggingFace models declare Python dependencies, so cargo packages are not covered.
epsschance of exploitation in 30 days
xyz scoreCyberXYZ composite out of 10
fig. 01 — RUSTSEC-2017-0007, the advisory selected below
// 1 advisories
RUSTSEC-2017-0007
UNKNOWNAccording to the developers this crate is no longer maintained.
The suggested alternative is lz4-compression, a maintained fork of lz4-compress.
See also lz-fear which is compatible with the reference LZ4 implementation in C, but not with lz4-compress.
Checked 2026-10-04 at 01:14 UTC. The most recent advisory here was published 2017-04-17. Updated continuously from NVD, GHSA, OSV and CNA feeds.