CVE-2026-27171: Zlib

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.

Affected products

  • Zlib Zlib: from 1.2.12, before 1.3.2 (fixed in 1.3.2)

Published 2026-02-18. Last modified 2026-06-17.