CVE-2026-4176

Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib. Compress::Raw::Zlib is included in the Perl package as a dual-life core module, and is vulnerable to CVE-2026-3381 due to a vendored version of zlib which has several vulnerabilities, including CVE-2026-27171. The bundled Compress::Raw::Zlib was updated to version 2.221 in Perl blead commit c75ae9cc164205e1b6d6dbd57bd2c65c8593fe94.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:perl:perl:*:*:*:*:*:*:*:*
cpe:2.3:a:perl:perl:*:*:*:*:*:*:*:*
cpe:2.3:a:perl:perl:*:*:*:*:*:*:*:*

History

22 Apr 2026, 17:31

Type Values Removed Values Added
First Time Perl perl
Perl
CWE NVD-CWE-Other
CPE cpe:2.3:a:perl:perl:*:*:*:*:*:*:*:*
References () https://github.com/Perl/perl5/commit/c75ae9cc164205e1b6d6dbd57bd2c65c8593fe94 - () https://github.com/Perl/perl5/commit/c75ae9cc164205e1b6d6dbd57bd2c65c8593fe94 - Patch
References () https://lists.security.metacpan.org/cve-announce/msg/37638919/ - () https://lists.security.metacpan.org/cve-announce/msg/37638919/ - Third Party Advisory
References () https://metacpan.org/release/PMQS/Compress-Raw-Zlib-2.221/source/Changes - () https://metacpan.org/release/PMQS/Compress-Raw-Zlib-2.221/source/Changes - Release Notes
References () https://metacpan.org/release/SHAY/perl-5.40.4/changes - () https://metacpan.org/release/SHAY/perl-5.40.4/changes - Release Notes
References () https://metacpan.org/release/SHAY/perl-5.42.2/changes - () https://metacpan.org/release/SHAY/perl-5.42.2/changes - Release Notes
References () https://www.cve.org/CVERecord?id=CVE-2026-3381 - () https://www.cve.org/CVERecord?id=CVE-2026-3381 - Third Party Advisory
References () http://www.openwall.com/lists/oss-security/2026/03/30/2 - () http://www.openwall.com/lists/oss-security/2026/03/30/2 - Mailing List, Third Party Advisory
Summary
  • (es) Las versiones de Perl desde la 5.9.4 anteriores a la 5.40.4-RC1, desde la 5.41.0 anteriores a la 5.42.2-RC1, y desde la 5.43.0 anteriores a la 5.43.9 contienen una versión vulnerable de Compress::Raw::Zlib. Compress::Raw::Zlib está incluido en el paquete de Perl como un módulo central de doble vida, y es vulnerable a CVE-2026-3381 debido a una versión empaquetada de zlib que tiene varias vulnerabilidades, incluyendo CVE-2026-27171. El Compress::Raw::Zlib empaquetado fue actualizado a la versión 2.221 en el commit de Perl blead c75ae9cc164205e1b6d6dbd57bd2c65c8593fe94.

30 Mar 2026, 16:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

30 Mar 2026, 06:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2026/03/30/2 -

29 Mar 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-29 21:16

Updated : 2026-04-22 17:31


NVD link : CVE-2026-4176

Mitre link : CVE-2026-4176

CVE.ORG link : CVE-2026-4176


JSON object : View

Products Affected

perl

  • perl