Vulnerabilities
Vulnerable Software
Zlib:  >> Zlib  >> 1.3.1.2  Security Vulnerabilities
zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.
CVSS Score
2.9
EPSS Score
0.002
Published
2026-02-18
zlib versions up to and including 1.3.1.2 include a global buffer overflow in the untgz utility located under contrib/untgz. The vulnerability is limited to the standalone demonstration utility and does not affect the core zlib compression library. The flaw occurs when a user executes the untgz command with an excessively long archive name supplied via the command line, leading to an out-of-bounds write in a fixed-size global buffer.
CVSS Score
4.6
EPSS Score
0.004
Published
2026-01-07


Contact Us

Shodan ® - All rights reserved