CVE-2026-27820Disclosure(ruby-lang / zlib)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch ruby-lang zlib systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

zlib is a Ruby interface for the zlib compression/decompression library. Versions 3.0.0 and below, 3.1.0, 3.1.1, 3.2.0 and 3.2.1 contain a buffer overflow vulnerability in the Zlib::GzipReader. The zstream_buffer_ungets function prepends caller-provided bytes ahead of previously produced output but fails to guarantee the backing Ruby string has enough capacity before the memmove shifts the existing data. This can lead to memory corruption when the buffer length exceeds capacity. This issue has been fixed in versions 3.0.1, 3.1.2 and 3.2.3.

0.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-120CWE-131

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • zlib

Threat summary

  • Patch or workaround signal is available
  • 12 mentions across 9 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 9 signals
  • Disclosure: 6 classified signals
  • General: 2 classified signals
  • Peaked 8d ago at 3 mentions (2026-03-05); latest day: 1
  • 12 total mentions across 9 days

Affected systems

Vendors
Products
zlib

Deep dive

Activity timeline12 mentions / 9d
01223Mentions · 2026-03-05: 3Mentions · 2026-03-07: 1Mentions · 2026-03-11: 1Mentions · 2026-03-26: 1Mentions · 2026-03-31: 1Mentions · 2026-04-17: 2Mentions · 2026-04-23: 1Mentions · 2026-05-26: 1Mentions · 2026-07-02: 1Patch / Workaround · 2026-03-05: 1Patch / Workaround · 2026-03-11: 1Patch / Workaround · 2026-03-26: 1Patch / Workaround · 2026-04-23: 1Technical Details · 2026-03-05: 3Technical Details · 2026-03-07: 1Technical Details · 2026-03-11: 1Technical Details · 2026-03-31: 1Technical Details · 2026-04-17: 1Technical Details · 2026-05-26: 1Technical Details · 2026-07-02: 103-0503-0703-1103-2603-3104-1704-2305-2607-02
Signal classification3 categories
Disclosure
650.0%
Patch
433.3%
General
216.7%
Referenced assets13 URLs
Classification over time
DateTotalLabels
2026-03-053
Disclosure2Patch1
2026-03-071
Disclosure1
2026-03-111
Patch1
2026-03-261
Patch1
2026-03-311
Disclosure1
2026-04-172
Disclosure1General1
2026-04-231
Patch1
2026-05-261
General1
2026-07-021
Disclosure1
Full discourse12 posts
  • Hiroshi SHIBATA@hsbt
    Patch

    I published CVE-2026-27820 that is Buffer overflow vulnerability in Zlib::GzipReader. https://www.ruby-lang.org/en/news/2026/03/05/buffer-overflow-zlib-cve-2026-27820/ The patched version is available in https://github.com/ruby/zlib/releases/tag/v3.2.3 and https://rubygems.org/gems/zlib/versions/3.2.3

    Post summary

    Ruby disclosed CVE-2026-27820, a buffer overflow in Zlib::GzipReader, and released a patched version v3.2.3 with update links.

    0501151.2K
    7.6K followersView on X
  • RubyOnRails.BA@RubyOnRailsBa
    Disclosure

    CVE-2026-27820: Buffer overflow vulnerability in Zlib::GzipReader | Ruby (from 27/03/2026) #ruby #rubyonrails #programming #CVE-2026-27820: #Buffer #overflow #vulnerability #Zlib::GzipReader https://www.rubyonrails.ba/link/cve-2026-27820-buffer-overflow-vulnerability-in-zlib-gzipreader-ruby

    Post summary

    A new buffer overflow vulnerability (CVE-2026-27820) affecting Ruby’s Zlib::GzipReader has been announced; no exploit code, PoC, or patch details are provided.

    0101059
    479 followersView on X
  • RUBYLAND@rubylandnews
    Disclosure

    Ruby News ➜ CVE-2026-27820: Buffer overflow vulnerability in Zlib::GzipReader https://www.ruby-lang.org/en/news/2026/03/05/buffer-overflow-zlib-cve-2026-27820/

    Post summary

    Ruby’s news releases a new CVE-2026‑27820, identifying a buffer overflow in Zlib::GzipReader; no PoC, exploit, or patch information is disclosed in the snippet.

    01010234
    2.7K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Disclosure

    TRC analysis shows GPT-5.5-Cyber autonomously developed fuzzing harnesses that discovered critical buffer overflow vulnerabilities in zlib (CVE-2026-27820, CVSS 9.8). The AI completed weeks of expert work in a single day. This demonstrates how AI is accelerating both vulnerability discovery and potential exploit development. #ZeroDay #ThreatIntel 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/field-reports-from-patch-the-planet-2026

    Post summary

    AI-generated fuzzing harnesses discovered a critical buffer overflow in zlib (CVE‑2026‑27820, CVSS 9.8), illustrating rapid vulnerability discovery capabilities.

    0000069
    1.9K followersView on X
  • Lyiase@lyiase
    General

    Rubyのzlib脆弱性のCVE-2026-27820、 NVD が付けたCVSSv3.1 = 9.8 (CRITICAL) GitHub が付けたCVSSv4.0 = 1.7 (LOW) なんだけどこんなに違うことある…? https://nvd.nist.gov/vuln/detail/CVE-2026-27820

    Post summary

    The message simply points out Ruby's zlib CVE‑2026‑27820, notes the stark difference in CVSS scores from NVD and GitHub, and links to the NVD entry.

    00000184
    4.0K followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Patch

    🔍 Lambda Watchdog detected that CVE-2026-27820 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/480 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    AWS Lambda base images have removed CVE‑2026‑27820, indicating the vulnerability has been patched or mitigated.

    0000058
    31 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    General

    🚨 New UNKNOWN CVE detected in AWS Lambda 🚨 CVE-2026-27820 impacts zlib in 2 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/480 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless

    Post summary

    A new CVE (CVE-2026-27820) affecting zlib in AWS Lambda base images has been reported, though no detailed technical information, PoC, exploit code, or patch details are provided in the brief.

    0000040
    34 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27820 zlib is a Ruby interface for the zlib compression/decompression library. Versions 3.0.0 and below, 3.1.0, 3.1.1, 3.2.0 and 3.2.1 contain a buffer overflow vulnerabili… https://www.cve.org/CVERecord?id=CVE-2026-27820

    Post summary

    The entry announces a buffer overflow flaw in the Ruby zlib interface, listing vulnerable versions but providing no exploitation, patch, or PoC details.

    0000098
    57.2K followersView on X
  • ChangeWatch@changewatchdev
    Patch

    Ruby enters security-only maintenance; get 3.3.11 zlib CVE fix If you run Ruby 3.3 in production, this release matters because 3.3 is leaving normal maintenance: 3.3.11 includes a zlib gem update that addresses CVE-2026-27820, but going… Read more → http://changewatch.dev/explore/f716258d-d523-427c-910e-aa6a57732d02

    Post summary

    Ruby 3.3.11 releases a zlib gem update that fixes CVE-2026-27820, marking the start of security‑only maintenance for Ruby 3.3.

    0000060
  • ruby-news.kr@rubynewskr
    Patch

    Ruby 3.4.9 정식 버전 출시 Ruby 3.4.9 버전이 공식 출시되었으며, zlib 젬의 버퍼 오버플로우 보안 취약점(CVE-2026-27820)을 해결하는 업데이트가 포함되었습니다. https://ruby-news.kr/articles/ruby-3-4-9-released

    Post summary

    Ruby 3.4.9 has been released with an update that patches CVE-2026-27820, a buffer overflow in the zlib gem, providing security remediation.

    0000043
    17 followersView on X
  • RUBYLAND@rubylandnews
    Disclosure

    RubySec ➜ CVE-2026-27820 (zlib): Buffer overflow vulnerability in Zlib::GzipReader https://rubysec.com/advisories/CVE-2026-27820/

    Post summary

    An advisory was released for CVE‑2026‑27820, noting a buffer overflow in Ruby's Zlib::GzipReader, without any mention of exploits, PoC, or patches.

    00000131
    2.7K followersView on X
  • ruby-news.kr@rubynewskr
    Disclosure

    CVE-2026-27820: Zlib::GzipReader의 버퍼 오버플로우 취약점 보안 권고 Ruby의 Zlib::GzipReader 클래스에서 메모리 손상을 유발할 수 있는 버퍼 오버플로우 취약점(CVE-2026-27820)이 발견되어 주의가 요구됩니다. https://ruby-news.kr/articles/buffer-overflow-zlib-cve-2026-27820

    Post summary

    CVE-2026-27820 is a newly discovered buffer‑overflow flaw in Ruby's Zlib::GzipReader that can lead to memory corruption; no exploit or patch information is provided.

    0000064
    17 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appruby-langzlib-ruby-

Explore more