CVE-2026-22184

HIGH

zlib <= 1.3.1.2 - Global Buffer Overflow in untgz Utility via Long Archive Name

Title source: llm
STIX 2.1

Description

zlib versions up to and including 1.3.1.2 include a global buffer overflow in the untgz utility located under contrib/untgz. The vulnerability is limited to the standalone demonstration utility and does not affect the core zlib compression library. The flaw occurs when a user executes the untgz command with an excessively long archive name supplied via the command line, leading to an out-of-bounds write in a fixed-size global buffer.

References (5)

Core 5
Core References
Product product
https://zlib.net/
Mailing List, Third Party Advisory technical-description exploit
https://seclists.org/fulldisclosure/2026/Jan/3

Scores

CVSS v3 7.8
EPSS 0.0021
EPSS Percentile 11.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-787
Status published
Products (2)
zlib/zlib < 1.3.1.2
zlib software/zlib < 1.3.1.2
Published Jan 07, 2026
Tracked Since Feb 18, 2026