LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →

CVE-2026-4176 - Vulnerability Analysis

CriticalCVSS: 9.8

Last Updated: March 30, 2026

Perl - Undefined

Published: March 29, 2026Updated: March 30, 2026Remote Exploitable

Overview

Perl 5.9.4 < versions < 5.40.4-RC1, 5.41.0 < versions < 5.42.2-RC1, and 5.43.0 < versions < 5.43.9 contain a vulnerability in Compress::Raw::Zlib due to a vendored zlib with multiple vulnerabilities, letting attackers exploit zlib flaws, exploit requires crafted input.

Severity & Score

Severity: Critical
CVSS Score: 9.8
EPSS Score: 1.9%(Probability of exploitation in next 30 days)

Impact

Attackers can exploit zlib vulnerabilities to cause potential denial of service or code execution.

Mitigation

Update to Perl version including Compress::Raw::Zlib 2.221 or later.

Social Media Activity(1 post)

TheHackerWire
TheHackerWire
@thehackerwire
Mar 30, 2026

šŸ”“ CVE-2026-4176 - Critical (9.8) Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib. Compress::Raw::Zlib is included in the Perl package as a dual-life core module, and is vulne... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-4176/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-4176
Severity
Critical
CVSS Score
9.8
Type
undefined
Status
unconfirmed
EPSS
1.9%
Social Posts
1

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Score

1.9%Probability of exploitation in the next 30 days