Logo
vulnerabilityCVE-2026-4176
Name
CVE-2026-4176
Source
NVD ( link)Debian ( link)
Description
Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib. Compress::Raw::Zlib is included in the Perl package as a dual-life core module, and is vulnerable to CVE-2026-3381 due to a vendored version of zlib which has several vulnerabilities, including CVE-2026-27171. The bundled Compress::Raw::Zlib was updated to version 2.221 in Perl blead commit c75ae9cc164205e1b6d6dbd57bd2c65c8593fe94.
CWEs
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
perl
False Positive

Vulnerability Ratings#


9.8
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
5.40.4
Not Affected
buildroot
master
5.42.2
Not Affected
openwrt
master
5.40.0-r6
Exploitable
openwrt
openwrt-25.12
5.40.0-r6
Exploitable
yocto
kirkstone
5.34.3
Exploitable
yocto
master
5.42.2
False Positive