Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-22184

34
FAUCET Score

CVE-2026-22184 is a critical global buffer overflow vulnerability affecting zlib versions up to 1.3.1.2, specifically within the untgz utility. This flaw occurs when a user executes untgz with an excessively long archive name, leading to an out-of-bounds write. The core zlib compression library is not affected. Rated with a CVSS score of 9.8 (Critical), this vulnerability has a network attack vector, low complexity, and can result in high impacts to confidentiality, integrity, and availability. Its EPSS score is low, suggesting a low probability of exploitation in the wild. Currently, there is no known active exploitation, nor is public exploit code available on platforms like Metasploit or ExploitDB. Despite this, the vulnerability has garnered significant community discussion, with 12 mentions, indicating notable awareness among cybersecurity professionals.

Impacted Technologies

VendorProductVersion(s)CPE
<= 1.3.1.2CPE matchmatch criteria
cpe:2.3:a:zlib:zlib:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

4.6MEDIUM

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
LOCAL
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
ACTIVE
VS Confidentiality
LOW
VS Integrity
NONE
VS Availability
LOW
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.38%
Probability of exploitation in next 30 days
EPSS Percentile
30.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0038 is in the 11th percentile among its peer group of 51,551 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (10)

redhatend of lifevia redhat_api
Product: Logging Subsystem for Red Hat OpenShiftFixed in: openshift-logging/elasticsearch6-rhel9
redhatend of lifevia redhat_api
Product: Logging Subsystem for Red Hat OpenShiftFixed in: openshift-logging/elasticsearch-operator-bundle
redhatend of lifevia redhat_api
Product: Logging Subsystem for Red Hat OpenShiftFixed in: openshift-logging/elasticsearch-proxy-rhel9
redhatend of lifevia redhat_api
Product: Logging Subsystem for Red Hat OpenShiftFixed in: openshift-logging/elasticsearch-rhel9-operator
redhatend of lifevia redhat_api
Product: Logging Subsystem for Red Hat OpenShiftFixed in: openshift-logging/fluentd-rhel9
redhatend of lifevia redhat_api
Product: Logging Subsystem for Red Hat OpenShiftFixed in: openshift-logging/kibana6-rhel8
redhatend of lifevia redhat_api
Product: Logging Subsystem for Red Hat OpenShiftFixed in: openshift-logging/logging-curator5-rhel9
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: mingw-zlib
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: mingw-zlib
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: mingw-zlib

Vendor Advisories (2)

microsoft2026-Jan/CVE-2026-22184Critical

zlib <= 1.3.1.2 untgz Global Buffer Overflow in TGZfname()

Jan 13, 2026
redhatCVE-2026-22184Important

zlib: zlib: Arbitrary code execution via buffer overflow in untgz utility

Jan 7, 2026

References

access.redhat.com / security/cve/CVE-2026-22184
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-22184.json
cert-portal.siemens.com / productcert/html/ssa-470355.html
github.com / madler/zlib/issues/1142
Issue Tracking
github.com / madler/zlib
Product
seclists.org / fulldisclosure/2026/Jan/3
Mailing ListThird Party Advisory
vulncheck.com / advisories/zlib-untgz-global-buffer-overflow-in-tgzfname
Third Party Advisory
zlib.net
Product