๐Ÿ” CVE Alert

CVE-2026-4176

CRITICAL 9.8

Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
1th

Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib. Compress::Raw::Zlib is included in the Perl package as a dual-life core module, and is vulnerable to CVE-2026-3381 due to a vendored version of zlib which has several vulnerabilities, including CVE-2026-27171. The bundled Compress::Raw::Zlib was updated to version 2.221 in Perl blead commit c75ae9cc164205e1b6d6dbd57bd2c65c8593fe94.

CWE CWE-1395
Vendor shay
Product perl
Published Mar 29, 2026
Last Updated Mar 30, 2026
Stay Ahead of the Next One

Get instant alerts for shay perl

Be the first to know when new critical vulnerabilities affecting shay perl are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

SHAY / perl
5.9.4 < 5.40.4-RC1 5.41.0 < 5.42.2-RC1 5.43.0 < 5.43.9

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
cve.org: https://www.cve.org/CVERecord?id=CVE-2026-3381 lists.security.metacpan.org: https://lists.security.metacpan.org/cve-announce/msg/37638919/ github.com: https://github.com/Perl/perl5/commit/c75ae9cc164205e1b6d6dbd57bd2c65c8593fe94 metacpan.org: https://metacpan.org/release/PMQS/Compress-Raw-Zlib-2.221/source/Changes metacpan.org: https://metacpan.org/release/SHAY/perl-5.40.4/changes metacpan.org: https://metacpan.org/release/SHAY/perl-5.42.2/changes openwall.com: http://www.openwall.com/lists/oss-security/2026/03/30/2

Credits

๐Ÿ” Bernhard Schmalhofer