CVE-2026-3381 PUBLISHED

Compress::Raw::Zlib versions through 2.219 for Perl use potentially insecure versions of zlib

Assigner: CPANSec
Reserved: 28.02.2026 Published: 05.03.2026 Updated: 05.03.2026

Compress::Raw::Zlib versions through 2.219 for Perl use potentially insecure versions of zlib.

Compress::Raw::Zlib includes a copy of the zlib library. Compress::Raw::Zlib version 2.220 includes zlib 1.3.2, which addresses findings fron the 7ASecurity audit of zlib. The includes fixs for CVE-2026-27171.

Product Status

Vendor PMQS
Product Compress::Raw::Zlib
Versions Default: unaffected
  • affected from 0 to 2.219 (incl.)

Solutions

Upgrade to Compress::Raw::Zlib 2.220 or later.

References

Problem Types

  • CWE-1395 Dependency on Vulnerable Third-Party Component CWE