# CVE-2026-3381

## Summary

- **CVE ID:** CVE-2026-3381
- **Severity:** UNKNOWN
- **CVSS Score:** 0
- **CWE:** CWE-1395
- **Published:** Mar 5, 2026
- **Last Modified:** Mar 16, 2026

## Description

Compress::Raw::Zlib versions through 2.219 for Perl use potentially insecure versions of zlib.

Compress::Raw::Zlib includes a copy of the zlib library. Compress::Raw::Zlib version 2.220 includes zlib 1.3.2, which addresses findings fron the 7ASecurity audit of zlib. The includes fixs for CVE-2026-27171.

## Affected Products

- PMQS — Compress::Raw::Zlib (0)

## References

- [CNA](https://metacpan.org/release/PMQS/Compress-Raw-Zlib-2.221/source/Changes)
- [CNA](https://www.zlib.net/)
- [CNA](https://github.com/madler/zlib)
- [CNA](https://github.com/madler/zlib/releases/tag/v1.3.2)
- [CNA](https://7asecurity.com/blog/2026/02/zlib-7asecurity-audit/)
- [CNA](https://www.cve.org/CVERecord?id=CVE-2026-27171)
- [CNA](https://github.com/pmqs/Compress-Raw-Zlib/issues/41)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.55%
- **EPSS Percentile:** 43.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._