CVE Tools

Gzip

18 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Gzip, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Gzip CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Gzip CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-062
2026-070
2026-080
2026-090

Severity

How the 18 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical16%
  • High633%
  • Medium739%
  • Low422%

Latest CVEs

The 15 most recently published vulnerabilities affecting Gzip.

  1. CVE-2026-41992Global Buffer Overflow in GNU gzip7.5
  2. CVE-2026-41991Predictable Temporary File in GNU gzip4.7
  3. CVE-2022-1271An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen file name (for example, a crafted file name), this can overwrite an attac...8.8
  4. CVE-2009-2624The huft_build function in inflate.c in gzip before 1.3.13 creates a hufts (aka huffman) table that is too small, which allows remote attackers to cause a denial of service (application crash or in...6.8
  5. CVE-2010-0001Integer underflow in the unlzw function in unlzw.c in gzip before 1.4 on 64-bit platforms, as used in ncompress and probably others, allows remote attackers to cause a denial of service (applicatio...6.8
  6. CVE-2006-4335Array index error in the make_table function in unlzh.c in the LZH decompression component in gzip 1.3.5, when running on certain platforms, allows context-dependent attackers to cause a denial of ...7.5
  7. CVE-2006-4334Unspecified vulnerability in gzip 1.3.5 allows context-dependent attackers to cause a denial of service (crash) via a crafted GZIP (gz) archive, which results in a NULL dereference.5.0
  8. CVE-2006-4336Buffer underflow in the build_tree function in unpack.c in gzip 1.3.5 allows context-dependent attackers to execute arbitrary code via a crafted leaf count table that causes a write to a negative i...7.5
  9. CVE-2006-4337Buffer overflow in the make_table function in the LHZ component in gzip 1.3.5 allows context-dependent attackers to execute arbitrary code via a crafted decoding table in a GZIP archive.7.5
  10. CVE-2006-4338unlzh.c in the LHZ component in gzip 1.3.5 allows context-dependent attackers to cause a denial of service (infinite loop) via a crafted GZIP archive.5.0
  11. CVE-2005-0758zgrep in gzip before 1.3.5 does not properly sanitize arguments, which allows local users to execute arbitrary commands via filenames that are injected into a sed script.4.6
  12. CVE-2005-1228Directory traversal vulnerability in gunzip -N in gzip 1.2.4 through 1.3.5 allows remote attackers to write to arbitrary directories via a .. (dot dot) in the original filename within a compressed ...5.0
  13. CVE-2005-0988Race condition in gzip 1.2.4, 1.3.3, and earlier, when decompressing a gzipped file, allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being d...3.7
  14. CVE-2004-1349gzip before 1.3 in Solaris 8, when called with the -f or -force flags, will change the permissions of files that are hard linked to the target files, which allows local users to view or modify thes...2.1
  15. CVE-2004-0970The (1) gzexe, (2) zdiff, and (3) znew scripts in the gzip package, as used by other packages such as ncompress, allows local users to overwrite files via a symlink attack on temporary files. NOTE...2.1

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store