logo

Critical Vulnerability in Perl Core Modules Leaves Systems Exposed

ID: fb1bd542-b076-56e4-9594-25c1bf67ab34

STIX ID: report--fb1bd542-b076-56e4-9594-25c1bf67ab34

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-03-31

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical supply-chain vulnerability (CVE-2026-4176, CVSS 9.8) has been identified in Perl's Compress::Raw::Zlib module due to a vendored, vulnerable zlib that includes additional CVEs; multiple Perl 5.x releases are affected and the recommended mitigations are upgrading to patched Perl releases (e.g., 5.40.4, 5.42.2 or later) or installing Compress::Raw::Zlib 2.220+ into the @INC path, while some distributions mitigate by using an updated system zlib (>= 1.3.2).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.