CVE-2026-27171

medium

Description

zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.

References

https://ostif.org/zlib-audit-complete/

https://github.com/madler/zlib/releases/tag/v1.3.2

https://github.com/madler/zlib/issues/904

https://7asecurity.com/reports/pentest-report-zlib-RC1.1.pdf

https://7asecurity.com/blog/2026/02/zlib-7asecurity-audit/

Details

Source: Mitre, NVD

Published: 2026-02-18

Updated: 2026-03-25

Risk Information

CVSS v2

Base Score: 4.6

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 5.5

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium

EPSS

EPSS: 0.00006