Vulnerability record · CVE-2026-4176 · published 29 March 2026
CVE-2026-4176: Perl vulnerability
Perl · Perl
Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib. Compress::Raw::Zlib is included in the Perl package as a dual-life core module, and is vulnerable to CVE-2026-3381 due to a vendored version of zlib which has several vulnerabilities, including CVE-2026-27171. The bundled Compress::Raw::Zlib was updated to version 2.221 in Perl blead commit c75ae9cc164205e1b6d6dbd57bd2c65c8593fe94.
Description
Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib. Compress::Raw::Zlib is included in the Perl package as a dual-life core module, and is vulnerable to CVE-2026-3381 due to a vendored version of zlib which has several vulnerabilities, including CVE-2026-27171. The bundled Compress::Raw::Zlib was updated to version 2.221 in Perl blead commit c75ae9cc164205e1b6d6dbd57bd2c65c8593fe94.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/Perl/perl5/commit/c75ae9cc164205e1b6d6dbd57bd2c65c8593fe94 | Patch |
| https://lists.security.metacpan.org/cve-announce/msg/37638919/ | Third Party Advisory |
| https://metacpan.org/release/PMQS/Compress-Raw-Zlib-2.221/source/Changes | Release Notes |
| https://metacpan.org/release/SHAY/perl-5.40.4/changes | Release Notes |
| https://metacpan.org/release/SHAY/perl-5.42.2/changes | Release Notes |
| https://www.cve.org/CVERecord?id=CVE-2026-3381 | Third Party Advisory |
| http://www.openwall.com/lists/oss-security/2026/03/30/2 | Mailing ListThird Party Advisory |
Track CVE-2026-4176 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-4176), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.