VulnerabilityAnalyzed
CVE-2026-27171
zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.
MEDIUM 5.5EPSS 0.22%
Does this matter?
Lower severity and a low EPSS score (0.22%). Track it; it rarely justifies an emergency change on its own.
Description
zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.22% probability · 12th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-1284
- Affected
- zlib/zlib
- Source
- cve@mitre.org
References
- https://7asecurity.com/blog/2026/02/zlib-7asecurity-audit/Product
- https://7asecurity.com/reports/pentest-report-zlib-RC1.1.pdfTechnical Description
- https://github.com/madler/zlib/issues/904Exploit, Issue Tracking
- https://github.com/madler/zlib/releases/tag/v1.3.2Release Notes
- https://ostif.org/zlib-audit-complete/Product
- https://7asecurity.com/reports/pentest-report-zlib-RC1.1.pdfTechnical Description
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.