CVE Tools

Zlib

21 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Zlib, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Zlib CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Zlib CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-021
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-011
2026-021
2026-031
2026-041
2026-050
2026-060
2026-070
2026-080
2026-091

Severity

How the 21 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical733%
  • High943%
  • Medium314%
  • Low210%

Latest CVEs

The 15 most recently published vulnerabilities affecting Zlib.

  1. CVE-2026-85091zlib 1.3.1.2 through 1.3.2 Heap Buffer Overflow via gz_vacate7.4
  2. CVE-2026-27820zlib: Buffer Overflow in Zlib::GzipReader ungetc via large input leads to memory corruption9.8
  3. CVE-2026-3381Compress::Raw::Zlib versions through 2.219 for Perl use potentially insecure versions of zlib9.8
  4. CVE-2026-27171zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.2.9
  5. CVE-2026-22184zlib <= 1.3.1.2 untgz Global Buffer Overflow in TGZfname()7.8
  6. CVE-2025-0725gzip integer overflow7.3
  7. CVE-2023-6992Memory corruption issues is Cloudflare zlib implementation4.0
  8. CVE-2023-45853MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supporte...9.8
  9. CVE-2022-37434zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected...9.8
  10. CVE-2018-25032zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.7.5
  11. BDU:2021-05117Уязвимость библиотеки сжатия zlib операционной системы «Аврора», позволяющая нарушителю вызвать отказ в обслуживании или оказать неопределенное воздействие7.3
  12. BDU:2021-03228Уязвимость библиотеки сжатия zlib операционной системы «Аврора», связанная с целочисленным переполнением, позволяющая нарушителю вызвать отказ в обслуживании или оказать неопределенное воздействие6.2
  13. CVE-2016-9843The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big-endian CRC calculation.9.8
  14. CVE-2016-9842The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers.8.8
  15. CVE-2016-9840inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.8.8

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store