Perl disclosed CVE-2026-4176, a vulnerability affecting releases from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, and from 5.43.0 before 5.43.9, because they shipped a vulnerable bundled version of the dual-life core module Compress::Raw::Zlib. The issue traces to the module’s vendored zlib copy, which is vulnerable to CVE-2026-3381 and includes additional flaws such as CVE-2026-27171. Some operating system distributions may avoid exposure if they link Perl against a patched system zlib version 1.3.2 or later, or if they have backported fixes.
The Perl project updated the bundled module in blead to version 2.221 and shipped fixes in Perl 5.40.4 and Perl 5.42.2, which include Compress::Raw::Zlib 2.222. Follow-up discussion on the oss-sec mailing list clarified that remediation guidance should explicitly state that affected installations can also be fixed by installing Compress::Raw::Zlib 2.222 from CPAN so it overrides the vulnerable core module in @INC; earlier guidance had noted 2.220 or later as a workaround.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
On 2026-03-30, the CVE record for CVE-2026-4176 was updated to include a CVSS v3.1 vector of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H and an Openwall oss-security reference. This expanded the public vulnerability metadata beyond the initial disclosure and remediation details.
A follow-up oss-sec discussion noted that any affected Perl version can be remediated by installing Compress::Raw::Zlib 2.222 from CPAN so it overrides the vulnerable core module. The reply also reiterated that Perl 5.40.4 and 5.42.2 or later include the fixed module.
An oss-sec disclosure reported that Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, and from 5.43.0 before 5.43.9 were affected because they shipped a vulnerable bundled Compress::Raw::Zlib.
Perl released stable versions 5.40.4 and 5.42.2 including Compress::Raw::Zlib 2.222 as the fix for CVE-2026-4176. The issue affected Perl release lines that bundled vulnerable Compress::Raw::Zlib versions.
The Perl project updated the bundled dual-life core module Compress::Raw::Zlib in blead to version 2.221 to address the vulnerable vendored zlib copy implicated in CVE-2026-4176.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourcecvefeed.io
Open sourceseclists.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.