Cyber Resilience

CVE-2026-4176

Perl 5.9.4 – 5.40.4

Published
29 March 2026
Modified
22 April 2026
Patch / advisory
CVSS Score v3.1 9.8
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0068 49th percentile
Risk Priority 72 floored blend · peak EPSS

Summary

CVE-2026-4176 is a critical-severity an unspecified weakness vulnerability in Perl Perl. Its CVSS base score is 9.8 (Critical).

Operationally, ranked at the 49th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

Deeper analysis AI-assisted summary

Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.

CVE-2026-4176 affects Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, and from 5.43.0 before 5.43.9. The vulnerability stems from a vulnerable version of the Compress::Raw::Zlib module, which is bundled as a dual-life core module in the Perl package. This module vendors a version of zlib containing multiple vulnerabilities, including CVE-2026-3381 and CVE-2026-27171. The issue was addressed by updating Compress::Raw::Zlib to version 2.221 in Perl's blead commit c75ae9cc164205e1b6d6dbd57bd2c65c8593fe94. The vulnerability has a CVSS v3.1 base score of 9.8.

Remote attackers require no privileges, authentication, or user interaction to exploit this vulnerability over the network with low complexity. Successful exploitation can result in high impacts to confidentiality, integrity, and availability, as indicated by the CVSS vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.

Advisories recommend updating to patched Perl releases such as 5.40.4, 5.42.2-RC1, or 5.43.9, which incorporate the fixed Compress::Raw::Zlib version 2.221. Relevant announcements are available via MetaCPAN security lists and release changes for Compress-Raw-Zlib 2.221, perl-5.40.4, and perl-5.42.2. The upstream fix is detailed in the Perl GitHub commit c75ae9cc164205e1b6d6dbd57bd2c65c8593fe94.

EU & UK References

Vulnerability Data

Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib. Compress::Raw::Zlib is included in the Perl package as a dual-life core module, and is vulnerable to CVE-2026-3381 due to a…

more

vendored version of zlib which has several vulnerabilities, including CVE-2026-27171. The bundled Compress::Raw::Zlib was updated to version 2.221 in Perl blead commit c75ae9cc164205e1b6d6dbd57bd2c65c8593fe94.

CWE(s)

Related Threats

CVEs Like This One

CVE-2026-13221Same product: Perl Perl
CVE-2026-8376Same product: Perl Perl
CVE-2026-57432Same product: Perl Perl
CVE-2024-56406Same product: Perl Perl
CVE-2023-31484Same product: Perl Perl
CVE-2023-31486Same product: Perl Perl
CVE-2023-47039Same product: Perl Perl
CVE-2026-14739Same vendor: Perl
CVE-2026-10879Same vendor: Perl
CVE-2026-14380Same vendor: Perl

Affected Assets

perl
perl
5.9.4 — 5.40.4 · 5.41.0 — 5.42.2 · 5.43.0 — 5.43.9

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References