CVE-2026-27171Disclosure(zlib / zlib)

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch zlib zlib systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1284

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • zlib

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 3 mentions (2026-02-18); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
zlib

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-02-18: 3Mentions · 2026-03-15: 1Mentions · 2026-05-22: 1Patch / Workaround · 2026-03-15: 1Patch / Workaround · 2026-05-22: 1Technical Details · 2026-02-18: 2Technical Details · 2026-03-15: 1Technical Details · 2026-05-22: 102-1803-1505-22
Signal classification3 categories
Disclosure
240.0%
General
240.0%
Patch
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-183
Disclosure1General2
2026-03-151
Disclosure1
2026-05-221
Patch1
Full discourse5 posts
  • Pete Massiello@petem59
    Patch

    Zlib for IBM i, while not utilized by every shop, presents a significant vulnerability that warrants attention. Vulnerability Details: - **CVEID:** CVE-2026-27171 - **Description:** Zlib versions prior to 1.3.2 allow for increased CPU consumption through the functions crc32_combine64 and crc32_combine_gen64. This occurs because x2nmodp can perform right shifts within a loop that lacks a termination condition. - **CWE:** CWE-1284: Improper Validation of Specified Quantity in Input - **CVSS Source:** NVD - **CVSS Base Score:** 5.5 - **CVSS Vector:** (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H) Remediation/Fixes: **IBM i Release PTF Number(s):** - 7.6: SJ09728 - 7.5: SJ09726 - 7.4: SJ09723 - 7.3: SJ09723 It is crucial for users to apply the necessary patches to mitigate this vulnerability.

    Post summary

    IBM i users should apply the provided PTF patches (SJ09728, SJ09726, SJ09723) to mitigate CVE‑2026‑27171, a vulnerability with a CVSS score of 5.5 that allows high CPU consumption.

    00020107
    1.4K followersView on X
  • PurpleOps@PurpleOps_io
    Disclosure

    📢 𝐍𝐞𝐰 𝐂𝐕𝐄 𝐚𝐧𝐚𝐥𝐲𝐬𝐢𝐬 𝐣𝐮𝐬𝐭 𝐝𝐫𝐨𝐩𝐩𝐞𝐝! Explore the CVE-2026-27171 RCE flaw, its impact on Windows SMB, and practical steps to patch and defend your network for operational resilience. 🔗 Read the full breakdown → https://www.purple-ops.io/cybersecurity-threat-intelligence-blog/cve-2026-27171-rce-analysis/ What’s your take? Share with us!

    Post summary

    The post announces an analysis of CVE‑2026‑27171, describing it as an RCE flaw in Windows SMB with general patching guidance, but offers no proof‑of‑concept, exploit code, or evidence of active exploitation.

    0000043
    89 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-27171 📊 Severity: 2.9 🚨 Risk Level: Low 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-27171 #CVE-2026-27171 #CVE #Low #CyberSecurity #InfoSec https://t.co/kTDOCTtjtB

    Post summary

    The tweet merely announces the CVE‑2026‑27171 with a low severity score and minimal detail, providing no actionable information.

    0000044
    56 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27171 zlib CPU Consumption Vulnerability via Infinite Loop in CRC32 Combine Fu... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27171 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    A new CVE (CVE-2026-27171) has been announced, detailing a CPU consumption vulnerability in zlib caused by an infinite loop in the CRC32 Combine function.

    0000080
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-27171 zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination conditi… https://www.cve.org/CVERecord?id=CVE-2026-27171

    Post summary

    The post references CVE-2026-27171 in zlib, noting a CPU exhaustion vulnerability in crc32_combine64 and crc32_combine_gen64 due to a loop with no termination condition, but provides no information about PoC, exploits, active use, or mitigation.

    00000272
    56.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appzlibzlib---

Explore more