LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →

CVE-2026-4176 - Vulnerability Analysis

CriticalCVSS: 9.8

Last Updated: March 30, 2026

Perl - Undefined

Published: March 29, 2026Updated: March 30, 2026Remote Exploitable

Overview

Perl 5.9.4 < versions < 5.40.4-RC1, 5.41.0 < versions < 5.42.2-RC1, and 5.43.0 < versions < 5.43.9 contain a vulnerability in Compress::Raw::Zlib due to a vendored zlib with multiple vulnerabilities, letting attackers exploit zlib flaws, exploit requires crafted input.

Severity & Score

Severity: Critical
CVSS Score: 9.8
EPSS Score: 0.9%(Probability of exploitation in next 30 days)

Impact

Attackers can exploit zlib vulnerabilities to cause potential denial of service or code execution.

Mitigation

Update to Perl version including Compress::Raw::Zlib 2.221 or later.

Social Media Activity(2 posts)

Offensive Sequence
Offensive Sequence
@offseq
Mar 29, 2026

⚠️ CVE-2026-4176 (HIGH): Perl Compress::Raw::Zlib uses a vulnerable zlib, risking memory corruption or code execution. Affects 5.9.4 – 5.43.0. Update to Compress::Raw::Zlib 2.221+ ASAP! https://radar.offseq.com/threat/cve-2026-4176-cwe-1395-dependency-on-vulnerable-th-556b643e #OffSeq #Perl #Vuln #SysAdmin

View original post
Offensive Sequence
Offensive Sequence
@offseq
Mar 29, 2026

⚠️ CVE-2026-4176 (HIGH): Perl Compress::Raw::Zlib uses a vulnerable zlib, risking memory corruption or code execution. Affects 5.9.4 – 5.43.0. Update to Compress::Raw::Zlib 2.221+ ASAP! https://radar.offseq.com/threat/cve-2026-4176-cwe-1395-dependency-on-vulnerable-th-556b643e #OffSeq #Perl #Vuln #SysAdmin

View original post

Details

CVE ID
CVE-2026-4176
Severity
Critical
CVSS Score
9.8
Type
undefined
Status
unconfirmed
EPSS
0.9%
Social Posts
2

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Score

0.9%Probability of exploitation in the next 30 days