CVE-2026-4176
Published: March 29th, 2026
Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib.
Compress::Raw::Zlib is included in the Perl package as a dual-life core module, and is vulnerable to CVE-2026-3381 due to a vendored version of zlib which has several vulnerabilities, including CVE-2026-27171. The bundled Compress::Raw::Zlib was updated to version 2.221 in Perl blead commit c75ae9cc164205e1b6d6dbd57bd2c65c8593fe94.
CRITICAL
CVSS v3: 9.8
CVSS v3: 9.8
Status
| DocFilters Release | Package | State | Justification | Comment |
|---|---|---|---|---|
| 0.0.0.1 | zlib (1.3) | Needs Triage | ||
| 26.1.1 | zlib (1.3) | Needs Triage | ||
| 26.1 | zlib (1.3) | Needs Triage | ||
| 25.4 | zlib (1.3) | Needs Triage | ||
| 25.3 | zlib (1.3) | Needs Triage | ||
| 25.2 | zlib (1.3) | Needs Triage | ||
| 25.1.2 | zlib (1.3) | Needs Triage | ||
| 25.1.1 | zlib (1.3) | Needs Triage | ||
| 25.1 | zlib (1.3) | Needs Triage | ||
| 24.4 | zlib (1.3) | Needs Triage | ||
| 24.4.0 | zlib (1.3) | Needs Triage | ||
| 24.3 | zlib (1.3) | Needs Triage | ||
| 24.2.1 | zlib (1.3) | Needs Triage | ||
| 24.2 | zlib (1.3) | Needs Triage | ||
| 24.1 | zlib (1.3) | Needs Triage | ||
| 23.3 | zlib (1.3) | Needs Triage | ||
| 23.2.1 | zlib (1.2.12) | Needs Triage | ||
| 23.2 | zlib (1.2.12) | Needs Triage | ||
| 23.1 | zlib (1.2.12) | Needs Triage | ||
| 22.4 | zlib (1.2.12) | Needs Triage | ||
| 22.3 | zlib (1.2.12) | Needs Triage | ||
| 22.2 | zlib (1.2.12) | Needs Triage | ||
| 22.1 | zlib (1.2.11) | Needs Triage | ||
| 21.11.1 | zlib (1.2.11) | Needs Triage | ||
| 21.11 | zlib (1.2.11) | Needs Triage | ||
| 21.8.1 | zlib (1.2.11) | Needs Triage | ||
| 21.8 | zlib (1.2.11) | Needs Triage | ||
| 21.5.1 | zlib (1.2.11) | Needs Triage | ||
| 21.5.0 | zlib (1.2.11) | Needs Triage | ||
| 21.2.0 | zlib (1.2.11) | Needs Triage | ||
| 11.4.20 | zlib (1.2.11) | Needs Triage | ||
| 11.4.19.3667 | zlib (1.2.11) | Needs Triage | ||
| 11.4.18.3599 | zlib (1.2.11) | Needs Triage | ||
| 11.4.17 | zlib (1.2.11) | Needs Triage | ||
| 11.4.16.3445 | zlib (1.2.11) | Needs Triage | ||
| 11.4.15.3368 | zlib (1.2.11) | Needs Triage | ||
| 11.4.14.3263 | zlib (1.2.11) | Needs Triage | ||
| 11.4.13.3179 | zlib (1.2.11) | Needs Triage | ||
| 11.4.12.3054 | zlib (1.2.11) | Needs Triage | ||
| 11.4.11.3040 | zlib (1.2.11) | Needs Triage | ||
| 11.4.11.2990 | zlib (1.2.11) | Needs Triage | ||
| 11.4.10.2934 | zlib (1.2.11) | Needs Triage | ||
| 11.4.9.2878 | zlib (1.2.11) | Needs Triage | ||
| 11.4.8.2822 | zlib (1.2.11) | Needs Triage |
Severity score breakdown
Attack Complexity
LOW
Attack Vector
NETWORK
Availability Impact
HIGH
Base Score
9.8
Base Severity
CRITICAL
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Privileges Required
NONE
Scope
UNCHANGED
User Interaction
NONE
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Version
3.1