OVERVIEW CVE-2026-27820 is a buffer overflow vulnerability in the Ruby zlib library affecting Zlib::GzipReader functionality across multiple versions (3.0.0 and below, 3.1.0, 3.1.1, 3.2.0, and 3.2.1). The vulnerability exists in the zstream_buffer_ungets function, which fails to validate that the underlying Ruby string buffer has sufficient capacity before performing memory operations. This can result in memory corruption when buffer operations exceed allocated capacity. The vulnerability has been addressed in versions 3.0.1, 3.1.2, and 3.2.3. SEVERITY The vulnerability presents a memory corruption risk with a FAUCET Risk Score of 31.0/100, indicating moderate concern. Without an assigned CVSS score or detailed attack vector information, the precise attack complexity and conditions required for exploitation cannot be definitively stated. However, buffer overflow vulnerabilities of this nature typically require specific conditions to trigger and may be difficult to exploit reliably. The potential impact includes denial of service through application crashes and potentially arbitrary code execution if the memory corruption can be sufficiently controlled. EXPLOITATION STATUS Currently, there are no indicators of active exploitation in the wild. The vulnerability does not appear on the Known Exploited Vulnerabilities (KEV) catalog, is classified as inactive on relevant hotlists, and carries an EPSS score of 0.00018, suggesting minimal probability of exploitation in practice. Community attention and exploit code availability remain limited at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.0.1CPE matchmatch criteria | cpe:2.3:a:ruby-lang:zlib:*:*:*:*:*:ruby:*:* | ||
>= 3.1.0, < 3.1.2CPE matchmatch criteria | cpe:2.3:a:ruby-lang:zlib:*:*:*:*:*:ruby:*:* | ||
>= 3.2.0, < 3.2.3CPE matchmatch criteria | cpe:2.3:a:ruby-lang:zlib:*:*:*:*:*:ruby:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Ruby vulnerabilities
Jul 16, 2026Buffer Overflow in Zlib::GzipReader ungetc via large input leads to memory corruption
Apr 16, 2026zlib: Buffer Overflow in Zlib::GzipReader ungetc via large input leads to memory corruption
Apr 14, 2026CVE-2026-27820: Buffer overflow vulnerability in Zlib::GzipReader
Mar 5, 2026CVE-2026-27820: Buffer overflow vulnerability in Zlib::GzipReader
Mar 5, 2026