CVE-2026-4176Patch(perl / perl)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch perl perl systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib. Compress::Raw::Zlib is included in the Perl package as a dual-life core module, and is vulnerable to CVE-2026-3381 due to a vendored version of zlib which has several vulnerabilities, including CVE-2026-27171. The bundled Compress::Raw::Zlib was updated to version 2.221 in Perl blead commit c75ae9cc164205e1b6d6dbd57bd2c65c8593fe94.

0.5/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • perl

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 4 mentions (2026-03-30); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
perl

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-03-30: 4Mentions · 2026-03-31: 1Mentions · 2026-04-01: 1Patch / Workaround · 2026-03-30: 1Patch / Workaround · 2026-03-31: 1Patch / Workaround · 2026-04-01: 1Technical Details · 2026-03-30: 3Technical Details · 2026-03-31: 103-3003-3104-01
Signal classification3 categories
Patch
350.0%
Disclosure
233.3%
General
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-304
Disclosure2General1Patch1
2026-03-311
Patch1
2026-04-011
Patch1
Full discourse6 posts
  • Open Source Security mailing list@oss_security
    Patch

    CVE-2026-4176: Perl: Bundled vulnerable version of Compress::Raw::Zlib https://www.openwall.com/lists/oss-security/2026/03/30/1 Affects Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9. Upgrade Perl or install Compress::Raw::Zlib 2.220 or later from CPAN.

    Post summary

    CVE-2026-4176 exposes a bundled vulnerable Compress::Raw::Zlib in multiple Perl releases, but purchasing an upgrade to Perl or installing Compress::Raw::Zlib 2.220 or newer resolves the issue.

    020821.1K
    4.6K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Perl (CVE-2026-4176) faces a 9.8 CVSS flaw due to a vulnerable zlib module. Affecting versions since 5.9.4, it demands an urgent update. Learn how to patch. #Perl #CyberSecurity #InfoSec #Vulnerability #zlib #PatchNow #Programming #DevOps #SysAdmin #CVE https://securityonline.info/perl-critical-vulnerability-zlib-cve-2026-4176-patch/ https://t.co/wUYkrlppm1

    Post summary

    The post announces a high‑importance CVE in Perl’s zlib module, urges users to apply the available patch, and provides a link to the patch documentation.

    04061544
    12.3K followersView on X
  • キタきつね@foxbook
    Patch

    Perlコアモジュールの重大な脆弱性によりシステムが危険にさらされる Critical Vulnerability in Perl Core Modules Leaves Systems Exposed #DailyCyberSecurity (Mar 31) https://securityonline.info/perl-critical-vulnerability-zlib-cve-2026-4176-patch/

    Post summary

    The brief notice highlights a critical Perl core module vulnerability (CVE‑2026‑4176) and points to a patch article, but provides no details on exploits, PoCs, or active attacks.

    01010173
    4.8K followersView on X
  • CosmicBytez@CosmicBytez
    General

    Security Advisory: CVE-2026-4176: Perl Compress::Raw::Zlib Critical Vulnerability (CVSS 9.8) https://labs.cosmicbytez.ca/security/cve-2026-4176 #Cybersecurity #InfoSec #CVE #PatchNow

    Post summary

    The post issues a security advisory for CVE-2026-4176, a critical vulnerability in Perl’s Compress::Raw::Zlib module, and links to an external advisory page. No PoC, exploit code, or patch details are provided beyond the advisory itself.

    0000063
    1 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-4176 - Critical Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib. Compress::Raw::Zlib is included i... https://www.thehackerwire.com/vulnerability/CVE-2026-4176/ https://t.co/dvcDKl3rYR

    Post summary

    The snippet announces CVE‑2026‑4176 in Perl’s Compress::Raw::Zlib, indicating affected version ranges, without providing PoC, exploitation evidence, or patch information.

    0000068
    157 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4176 Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib. Compress::Raw… https://www.cve.org/CVERecord?id=CVE-2026-4176

    Post summary

    The text reports CVE-2026-4176, identifying Perl versions 5.9.4‑5.40.4‑RC1, 5.41.0‑5.42.2‑RC1, and 5.43.0‑5.43.9 as affected due to an issue in Compress::Raw::Zlib, with a link to the CVE record.

    0000098
    56.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appperlperl---

Explore more