CVE-2026-4176
Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib
CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
1th
Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib. Compress::Raw::Zlib is included in the Perl package as a dual-life core module, and is vulnerable to CVE-2026-3381 due to a vendored version of zlib which has several vulnerabilities, including CVE-2026-27171. The bundled Compress::Raw::Zlib was updated to version 2.221 in Perl blead commit c75ae9cc164205e1b6d6dbd57bd2c65c8593fe94.
| CWE | CWE-1395 |
| Vendor | shay |
| Product | perl |
| Published | Mar 29, 2026 |
| Last Updated | Mar 30, 2026 |
Stay Ahead of the Next One
Get instant alerts for shay perl
Be the first to know when new critical vulnerabilities affecting shay perl are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
SHAY / perl
5.9.4 < 5.40.4-RC1 5.41.0 < 5.42.2-RC1 5.43.0 < 5.43.9
References
cve.org: https://www.cve.org/CVERecord?id=CVE-2026-3381 lists.security.metacpan.org: https://lists.security.metacpan.org/cve-announce/msg/37638919/ github.com: https://github.com/Perl/perl5/commit/c75ae9cc164205e1b6d6dbd57bd2c65c8593fe94 metacpan.org: https://metacpan.org/release/PMQS/Compress-Raw-Zlib-2.221/source/Changes metacpan.org: https://metacpan.org/release/SHAY/perl-5.40.4/changes metacpan.org: https://metacpan.org/release/SHAY/perl-5.42.2/changes openwall.com: http://www.openwall.com/lists/oss-security/2026/03/30/2
Credits
๐ Bernhard Schmalhofer