Zlib is a foundational data-compression library embedded across an enormous range of software and infrastructure—from web servers and network utilities to embedded systems and container formats—making it one of the most critical single points of failure in the modern software supply chain. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, and its small product surface belies the amplification risk that flows from deep universal integration. The recurring weakness classes, including out-of-bounds writes, buffer overflows, and double-free conditions, reflect the low-level memory-handling demands of efficient compression algorithms. Defenders should treat Zlib disclosures as priority-one across all products and platforms that bundle or link the library, since remediation cascades through the entire ecosystem; live severity and exploit-availability counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zlib over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-25032HIGH zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches. | Mar 25, 2022 | 7.5 | 56 | NO | NO |
CVE-2003-0107HIGH Buffer overflow in the gzprintf function in zlib 1.1.4, when zlib is compiled without vsnprintf or when long inputs are truncated using vsnprintf, allows attackers to cause a denia | Mar 7, 2003 | 7.5 | 48 | NO | YES |
CVE-2022-37434CRITICAL zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHe | Aug 5, 2022 | 9.8 | 41 | NO | NO |
CVE-2023-45853CRITICAL MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip | Oct 14, 2023 | 9.8 | 35 | NO | NO |
CVE-2016-9841CRITICAL inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic. | May 23, 2017 | 9.8 | 35 | NO | NO |
CVE-2002-0059CRITICAL The decompression algorithm in zlib 1.1.3 and earlier, as used in many different utilities and packages, causes inflateEnd to release certain memory more than once (a "double free" | Mar 15, 2002 | 9.8 | 35 | NO | NO |
CVE-2026-22184HIGH zlib versions up to and including 1.3.1.2 include a global buffer overflow in the untgz utility located under contrib/untgz. The vulnerability is limited to the standalone demonstr | Jan 7, 2026 | 7.8 | 34 | NO | NO |
CVE-2016-9843CRITICAL The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big-endian CRC calculation. | May 23, 2017 | 9.8 | 33 | NO | NO |
CVE-2016-9842HIGH The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers. | May 23, 2017 | 8.8 | 33 | NO | NO |
CVE-2016-9840HIGH inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic. | May 23, 2017 | 8.8 | 33 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zlib.
Media articles that mention a CVE ID that affects a product developed by Zlib — matched by CVE ID, not by vendor name.