CVE-2026-4176

Communications: Dependency on Vulnerable Third-Party Component (CVE-2026-4176)

criticalEPSS 0.8%

Affected

  • Oracle/Communications 8.0.0..*
  • Oracle/Communications 7.4.1..*
  • Oracle/Communications 6.1.1-7.0.0..*
  • Oracle/Communications 8.0.1..*
  • Oracle/Communications 7.5.0-7.5.1..*
  • Oracle/Communications 7.6.0-7.8.0..*
  • Oracle/Communications 25.2.0.0.10..*

Description

Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib. Compress::Raw::Zlib is included in the Perl package as a dual-life core module, and is vulnerable to CVE-2026-3381 due to a vendored version of zlib which has several vulnerabilities, including CVE-2026-27171. The bundled Compress::Raw::Zlib was updated to version 2.221 in Perl blead commit c75ae9cc164205e1b6d6dbd57bd2c65c8593fe94.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

OracleCommunications
25.2.0.0.106.1.1-7.0.07.4.17.5.0-7.5.17.6.0-7.8.08.0.08.0.1

Metrics

9.8
Source: cna-v3
55.7 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
Show all metrics
Severity
critical
no public PoC known
0.8 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-03-29 20:50 UTC
CWE-1395

Weakness classes (CWE)

  • CWE-1395Class

    Dependency on Vulnerable Third-Party Component

    The product has a dependency on a third-party component that contains one or more known vulnerabilities.

    cwe.mitre.org →

References & sources