CVE-2026-4176
published 2026-03-29CVE-2026-4176: Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib…
PriorityP352critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.68%
48.5th percentile
Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib.
Compress::Raw::Zlib is included in the Perl package as a dual-life core module, and is vulnerable to CVE-2026-3381 due to a vendored version of zlib which has several vulnerabilities, including CVE-2026-27171. The bundled Compress::Raw::Zlib was updated to version 2.221 in Perl blead commit c75ae9cc164205e1b6d6dbd57bd2c65c8593fe94.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | perl | < perl 5.10.0-21 (bookworm) | perl 5.10.0-21 (bookworm) |
| perl | perl | >= 0 < 0 | 0 |
| perl | perl | >= 0 < 5.10.0-21 | 5.10.0-21 |
| perl | perl | >= 0 < 5.10.0-21 | 5.10.0-21 |
| perl | perl | >= 0 < 5.10.0-21 | 5.10.0-21 |
| perl | perl | >= 0 < 5.10.0-21 | 5.10.0-21 |
| perl | perl | >= 5.41.0 < 5.42.2 | 5.42.2 |
| perl | perl | >= 5.43.0 < 5.43.9 | 5.43.9 |
| perl | perl | >= 5.9.4 < 5.40.4 | 5.40.4 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv5.5MEDIUM
vendor_debian2.9LOW
vendor_redhat2.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Perl: Compress::Raw::Zlib: zlib: Perl: Multiple vulnerabilities due to an outdated vendored zlib library
vendor_redhat·2026-03-29·CVSS 2.9
CVE-2026-4176 [LOW] CWE-1104 Perl: Compress::Raw::Zlib: zlib: Perl: Multiple vulnerabilities due to an outdated vendored zlib library
Perl: Compress::Raw::Zlib: zlib: Perl: Multiple vulnerabilities due to an outdated vendored zlib library
Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib.
Compress::Raw::Zlib is included in the Perl package as a dual-life core module, and is vulnerable to CVE-2026-3381 due to a vendored version of zlib which has several vulnerabilities, including CVE-2026-27171. The bundled Compress::Raw::Zlib was updated to version 2.221 in Perl blead commit c75ae9cc164205e1b6d6dbd57bd2c65c8593fe94.
A flaw was found in Perl, stemming from its inclusion of an outdated `Compress::Raw::Zlib` module. This module bundles a vulnerable version of the `zlib` library, which is known to contain multiple securit
Debian
CVE-2026-4176: perl - Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from ...
vendor_debian·2026·CVSS 2.9
CVE-2026-4176 [LOW] CVE-2026-4176: perl - Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from ...
Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib. Compress::Raw::Zlib is included in the Perl package as a dual-life core module, and is vulnerable to CVE-2026-3381 due to a vendored version of zlib which has several vulnerabilities, including CVE-2026-27171. The bundled Compress::Raw::Zlib was updated to version 2.221 in Perl blead commit c75ae9cc164205e1b6d6dbd57bd2c65c8593fe94.
Scope: local
bookworm: resolved (fixed in 5.10.0-21)
bullseye: resolved (fixed in 5.10.0-21)
forky: resolved (fixed in 5.10.0-21)
sid: resolved (fixed in 5.10.0-21)
trixie: resolved (fixed in 5.10.0-21)
OSV
CVE-2026-4176: Perl versions from 5
osv·2026-03-29·CVSS 5.5
CVE-2026-4176 [MEDIUM] CVE-2026-4176: Perl versions from 5
Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib.
Compress::Raw::Zlib is included in the Perl package as a dual-life core module, and is vulnerable to CVE-2026-3381 due to a vendored version of zlib which has several vulnerabilities, including CVE-2026-27171. The bundled Compress::Raw::Zlib was updated to version 2.221 in Perl blead commit c75ae9cc164205e1b6d6dbd57bd2c65c8593fe94.
OSV
CVE-2026-4176: Perl versions from 5
osv·2026-03-29·CVSS 5.5
CVE-2026-4176 [MEDIUM] CVE-2026-4176: Perl versions from 5
Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib. Compress::Raw::Zlib is included in the Perl package as a dual-life core module, and is vulnerable to CVE-2026-3381 due to a vendored version of zlib which has several vulnerabilities, including CVE-2026-27171. The bundled Compress::Raw::Zlib was updated to version 2.221 in Perl blead commit c75ae9cc164205e1b6d6dbd57bd2c65c8593fe94.
GHSA
GHSA-q2q4-jjp8-f6m3: Perl versions from 5
ghsa_unreviewed·2026-03-29·CVSS 2.9
CVE-2026-4176 [LOW] GHSA-q2q4-jjp8-f6m3: Perl versions from 5
Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib.
Compress::Raw::Zlib is included in the Perl package as a dual-life core module, and is vulnerable to CVE-2026-3381 due to a vendored version of zlib which has several vulnerabilities, including CVE-2026-27171. The bundled Compress::Raw::Zlib was updated to version 2.221 in Perl blead commit c75ae9cc164205e1b6d6dbd57bd2c65c8593fe94.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-4176 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 2.9
CVE-2026-4176 [LOW] CVE-2026-4176 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-4176 :
Wolfi vulnerability analysis and mitigation
Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib.
Compress::Raw::Zlib is included in the Perl package as a dual-life core module, and is vulnerable to CVE-2026-3381 due to a vendored version of zlib which has several vulnerabilities, including CVE-2026-27171. The bundled Compress::Raw::Zlib was updated to version 2.221 in Perl blead commit c75ae9cc164205e1b6d6dbd57bd2c65c8593fe94.
Source : NVD
## 9.8
Score
Published March 29, 2026
Severity CRITICAL
CNA Score 9.8
Affected Technologies
Wolfi
Chainguard
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation P
Bugzilla
CVE-2026-4176 perl: Perl: Multiple vulnerabilities due to an outdated vendored zlib library [fedora-42]
bugzilla·2026-03-30·CVSS 9.8
CVE-2026-4176 [CRITICAL] CVE-2026-4176 perl: Perl: Multiple vulnerabilities due to an outdated vendored zlib library [fedora-42]
CVE-2026-4176 perl: Perl: Multiple vulnerabilities due to an outdated vendored zlib library [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-2026-58dd426edd (perl-5.40.4-520.fc42, perl-Devel-Cover-1.44-7.fc42, and 1 more) has been submitted as an update to Fedora 42.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-58dd426edd
---
FEDORA-2026-58dd426edd has been pushed to the Fedora 42 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-58dd426edd`
You can provide
Bugzilla
CVE-2026-4176 Perl: Compress::Raw::Zlib: zlib: Perl: Multiple vulnerabilities due to an outdated vendored zlib library
bugzilla·2026-03-29·CVSS 5.5
CVE-2026-4176 [MEDIUM] CVE-2026-4176 Perl: Compress::Raw::Zlib: zlib: Perl: Multiple vulnerabilities due to an outdated vendored zlib library
CVE-2026-4176 Perl: Compress::Raw::Zlib: zlib: Perl: Multiple vulnerabilities due to an outdated vendored zlib library
Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib.
Compress::Raw::Zlib is included in the Perl package as a dual-life core module, and is vulnerable to CVE-2026-3381 due to a vendored version of zlib which has several vulnerabilities, including CVE-2026-27171. The bundled Compress::Raw::Zlib was updated to version 2.221 in Perl blead commit c75ae9cc164205e1b6d6dbd57bd2c65c8593fe94.
https://github.com/Perl/perl5/commit/c75ae9cc164205e1b6d6dbd57bd2c65c8593fe94https://lists.security.metacpan.org/cve-announce/msg/37638919/https://metacpan.org/release/PMQS/Compress-Raw-Zlib-2.221/source/Changeshttps://metacpan.org/release/SHAY/perl-5.40.4/changeshttps://metacpan.org/release/SHAY/perl-5.42.2/changeshttps://www.cve.org/CVERecord?id=CVE-2026-3381http://www.openwall.com/lists/oss-security/2026/03/30/2
2026-03-29
Published