CVE-2026-4176
Communications: Dependency on Vulnerable Third-Party Component (CVE-2026-4176)
Affected
- Oracle/Communications
8.0.0..* - Oracle/Communications
7.4.1..* - Oracle/Communications
6.1.1-7.0.0..* - Oracle/Communications
8.0.1..* - Oracle/Communications
7.5.0-7.5.1..* - Oracle/Communications
7.6.0-7.8.0..* - Oracle/Communications
25.2.0.0.10..*
Description
Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib. Compress::Raw::Zlib is included in the Perl package as a dual-life core module, and is vulnerable to CVE-2026-3381 due to a vendored version of zlib which has several vulnerabilities, including CVE-2026-27171. The bundled Compress::Raw::Zlib was updated to version 2.221 in Perl blead commit c75ae9cc164205e1b6d6dbd57bd2c65c8593fe94.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
25.2.0.0.106.1.1-7.0.07.4.17.5.0-7.5.17.6.0-7.8.08.0.08.0.1Metrics
Show all metrics
Weakness classes (CWE)
CWE-1395Class
Dependency on Vulnerable Third-Party Component
The product has a dependency on a third-party component that contains one or more known vulnerabilities.
cwe.mitre.org →
References & sources
- https://www.cve.org/CVERecord?id=CVE-2026-3381vendor-advisoryrelatedvdb-entry
- https://lists.security.metacpan.org/cve-announce/msg/37638919/vendor-advisory
- https://github.com/Perl/perl5/commit/c75ae9cc164205e1b6d6dbd57bd2c65c8593fe94patch
- https://metacpan.org/release/PMQS/Compress-Raw-Zlib-2.221/source/Changesrelease-notes
- https://metacpan.org/release/SHAY/perl-5.40.4/changesrelease-notes
- https://metacpan.org/release/SHAY/perl-5.42.2/changesrelease-notes
- http://www.openwall.com/lists/oss-security/2026/03/30/2