CVE-2026-22184
HIGHzlib <= 1.3.1.2 - Global Buffer Overflow in untgz Utility via Long Archive Name
Title source: llmDescription
zlib versions up to and including 1.3.1.2 include a global buffer overflow in the untgz utility located under contrib/untgz. The vulnerability is limited to the standalone demonstration utility and does not affect the core zlib compression library. The flaw occurs when a user executes the untgz command with an excessively long archive name supplied via the command line, leading to an out-of-bounds write in a fixed-size global buffer.
References (5)
Core 5
Core References
Issue Tracking
https://github.com/madler/zlib/issues/1142
Product product
https://zlib.net/
Mailing List, Third Party Advisory technical-description
exploit
https://seclists.org/fulldisclosure/2026/Jan/3
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/zlib-untgz-global-buffer-overflow-in-tgzfname
Scores
CVSS v3
7.8
EPSS
0.0021
EPSS Percentile
11.2%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
total
Details
CWE
CWE-787
Status
published
Products (2)
zlib/zlib
< 1.3.1.2
zlib software/zlib
< 1.3.1.2
Published
Jan 07, 2026
Tracked Since
Feb 18, 2026