CVE-2026-3381
Compress::Raw::Zlib versions through 2.219 for Perl use potentially insecure versions of zlib. Compress::Raw::Zlib includes a copy of the zlib library. Compress::Raw::Zlib version 2.220 includes zlib 1.3.2, which addresses findings fron the 7ASecurity audit of zlib. The includes fixs for CVE-2026-27171.
Scoring
- CVSS base score
- 0
- EPSS probability
- 0.55%
- CWE
- CWE-1395
- Published
- 2026-03-05
- Last modified
- 2026-03-16
Affected products
- PMQS Compress::Raw::Zlib
Weakness type
Related vulnerabilities
- CVE-2026-69713 — Windows Secure Boot Security Feature Bypass Vulnerability
- CVE-2026-58235 — Use of Vulnerable Third-Party Component in SAP NetWeaver AS Java (Adobe Document Services)
- CVE-2026-58586 — Image::WebP versions before 0.3.0 for Perl bundle a vulnerable version of libwebp
- CVE-2026-16634 — TOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99
- CVE-2026-55789 — Logto: SAML IdP injects user-controlled profile attributes raw into signed assertions, allowing privilege escalation at relying Service Providers
- CVE-2026-47906 — Dreamweaver Desktop | Dependency on Vulnerable Third-Party Component (CWE-1395)
- CVE-2026-8993 — Improper URL Handler Processing in D.Launcher 2 enables NTLM Credential Disclosure and SSRF attacks
- CVE-2025-31973 — HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'