High severity7.4NVD Advisory· Published Aug 24, 2026· Updated Oct 1, 2026
CVE-2026-76844
CVE-2026-76844
Description
zlib 1.2.11 through 1.3.2 contains a heap buffer overflow: after an underlying write() fails, gz_write() returns without resetting strm.next_in, leaving it pointed at the caller's buffer. A later gz* write call then derives a position from the stale pointer and writes past a heap allocation; any write() failure reaches it, including EPIPE on a blocking descriptor, and in versions before 1.3.1.2 the failed write must be followed by a gzclearerr() call.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
15- github.com/advisories/GHSA-g84c-rxfj-3j2cghsaADVISORY
- gist.github.com/thesmartshadow/e0b9481792afb7c31e86fee1ff084490nvd
- github.com/advisories/GHSA-wr3j-pwj9-hqq6ghsa
- github.com/madler/zlib/blob/v1.3.2/gzwrite.cnvd
- github.com/madler/zlib/commit/df84af25dc1942490e1d1c899a07619152a46148nvd
- github.com/webpack/webpack-dev-middleware/blob/v8.1.1/src/middleware.jsghsa
- github.com/webpack/webpack-dev-middleware/commit/13344e78b26d88fe9b7c8381a3860e248a52359bghsa
- github.com/webpack/webpack-dev-middleware/commit/cefccbac330c29052fc6dffe85fd292ea2ac782bghsa
- github.com/webpack/webpack-dev-middleware/pull/2404ghsa
- github.com/webpack/webpack-dev-middleware/releases/tag/v7.4.6ghsa
- github.com/webpack/webpack-dev-middleware/releases/tag/v8.3.0ghsa
- github.com/webpack/webpack-dev-middleware/security/advisories/GHSA-g84c-rxfj-3j2cghsa
- nvd.nist.gov/vuln/detail/CVE-2026-76844ghsa
- www.vulncheck.com/advisories/webpack-dev-middleware-path-traversal-via-offset-slice-on-a-non-slash-terminated-publicpathghsa
- www.vulncheck.com/advisories/zlib-1.3.1.2-through-1.3.2-heap-buffer-overflow-via-gz-vacatenvd
News mentions
0No linked articles in our index yet.