
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3381 is a vulnerability in the Perl module Compress::Raw::Zlib arising from its use of a bundled, potentially insecure version of the zlib compression library. All versions of Compress::Raw::Zlib through 2.219 are affected; version 2.220 and later include zlib 1.3.2, which addresses the underlying issues identified in the 7ASecurity audit of zlib (including fixes for the related CVE-2026-27171). The vulnerability was published on March 5, 2026, and assigned by CPANSec (RedHat CVE). It carries a CVSS v3.1 base score of 9.8 (Critical) (RedHat CVE, Microsoft MSRC).
The root cause is classified under CWE-1104 (Use of Unmaintained Third Party Components) and CWE-1284 (Improper Validation of Specified Quantity in Input). Compress::Raw::Zlib ships with a vendored copy of the zlib library rather than relying on the system-installed version; versions through 2.219 bundle zlib releases prior to 1.3.2, which contain vulnerabilities identified during the 7ASecurity security audit of zlib (7ASecurity Blog, zlib Release). The attack vector is network-based with low complexity and requires no authentication or user interaction, meaning any application that processes attacker-controlled compressed data via this module could be exploited (RedHat CVE). The upstream zlib 1.3.2 release (February 17, 2026) specifically addresses the 7ASecurity audit findings and is the basis for the fix (zlib Release).
Successful exploitation can result in complete compromise of confidentiality, integrity, and availability of affected systems, as reflected in the CVSS v3.1 score of 9.8 (RedHat CVE). Any Perl application that uses Compress::Raw::Zlib (directly or transitively through modules such as IO::Compress) to process untrusted compressed data is potentially at risk. The broad deployment of this module across Perl ecosystems — including enterprise products such as IBM Tivoli Network Manager — significantly widens the attack surface (IBM Advisory).
The primary remediation is to upgrade Compress::Raw::Zlib to version 2.220 or later, which bundles zlib 1.3.2 and addresses the identified vulnerabilities (Compress-Raw-Zlib Issue, zlib Release). Organizations should audit all systems running Perl applications that depend on Compress::Raw::Zlib versions 2.219 or earlier and prioritize patching given the critical CVSS score. OpenSUSE has issued updated packages for perl-Compress-Raw-Zlib (version 2.222), and IBM has released security bulletins for affected products such as IBM Tivoli Network Manager (IBM Advisory). No configuration-based workaround is available; upgrading the module is the only effective mitigation.
The vulnerability was discussed on the oss-security mailing list shortly after disclosure (oss-sec). Microsoft included CVE-2026-3381 in its March 2026 Patch Tuesday advisory, which received broad coverage from security media outlets including BleepingComputer and WinBuzzer (Microsoft MSRC). The Perl community discussed the fix via the perl5-porters mailing list, and the upstream Erlang/OTP project also committed a fix referencing this CVE, indicating broad ecosystem impact (Perl Porters).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."