VYPR

Zlib

by Madler

Source repositories

CVEs (2)

  • CVE-2026-22184HigJan 7, 2026
    risk 0.51cvss 7.8epss 0.00

    zlib versions up to and including 1.3.1.2 include a global buffer overflow in the untgz utility located under contrib/untgz. The vulnerability is limited to the standalone demonstration utility and does not affect the core zlib compression library. The flaw occurs when a user…

  • CVE-2026-85091HigSep 3, 2026
    risk 0.41cvss 7.4epss 0.01

    zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow by calling gzprintf() or gzvprintf() after a…