Severity
9.8CRITICALNVD
NVD5.5CNA2.9OSV5.5
EPSS
0.0%
top 99.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 18
Latest updateMar 29

Description

zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages12 packages

CVEListV5zlib/zlib< 1.3.2
NVDzlib/zlib1.2.121.3.2
debiandebian/zlib< zlib 1:1.3.dfsg+really1.3.2-1 (sid)
debiandebian/libcompress-raw-zlib-perl< libcompress-raw-zlib-perl 2.011-2 (bookworm)
CVEListV5pmqs/compress_raw_zlib2.219

🔴Vulnerability Details

11
OSV
CVE-2026-4176: Perl versions from 52026-03-29
OSV
CVE-2026-4176: Perl versions from 52026-03-29
CVEList
Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib2026-03-29
GHSA
GHSA-q2q4-jjp8-f6m3: Perl versions from 52026-03-29
OSV
CVE-2026-3381: Compress::Raw::Zlib versions through 22026-03-05

📋Vendor Advisories

7
Red Hat
Perl: Compress::Raw::Zlib: zlib: Perl: Multiple vulnerabilities due to an outdated vendored zlib library2026-03-29
Red Hat
compress-raw-zlib: Compress::Raw::Zlib: Vulnerabilities due to outdated zlib library2026-03-05
Red Hat
zlib: zlib: Denial of Service via infinite loop in CRC32 combine functions2026-02-18
Microsoft
zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.2026-02-10
Debian
CVE-2026-27171: zlib - zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_g...2026

🕵️Threat Intelligence

3
Wiz
CVE-2026-4176 Impact, Exploitability, and Mitigation Steps | Wiz
Wiz
CVE-2026-3381 Impact, Exploitability, and Mitigation Steps | Wiz
Wiz
CVE-2026-27171 Impact, Exploitability, and Mitigation Steps | Wiz