Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Zlib

First CVE: Mar 15, 2002Active for: 24 yearsTotal CVEs: 17
54.9
VTI Score
TOP TARGET

Zlib is a foundational data-compression library embedded across an enormous range of software and infrastructure—from web servers and network utilities to embedded systems and container formats—making it one of the most critical single points of failure in the modern software supply chain. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, and its small product surface belies the amplification risk that flows from deep universal integration. The recurring weakness classes, including out-of-bounds writes, buffer overflows, and double-free conditions, reflect the low-level memory-handling demands of efficient compression algorithms. Defenders should treat Zlib disclosures as priority-one across all products and platforms that bundle or link the library, since remediation cascades through the entire ecosystem; live severity and exploit-availability counts are shown alongside this summary.

FAUCET AI Generated
17
Total CVEs
More Total CVEs than 95% of tracked vendors
0.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 11% of tracked vendors
7.4
Avg CVSS Score
Higher Avg CVSS Score than 56% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Zlib over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 15, 2002
24 years ago
Most Recent CVE
Feb 18, 2026
156 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (17 CVEs).

17 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-25032HIGH
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
Mar 25, 20227.556NONO
CVE-2003-0107HIGH
Buffer overflow in the gzprintf function in zlib 1.1.4, when zlib is compiled without vsnprintf or when long inputs are truncated using vsnprintf, allows attackers to cause a denia
Mar 7, 20037.548NOYES
CVE-2022-37434CRITICAL
zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHe
Aug 5, 20229.841NONO
CVE-2023-45853CRITICAL
MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip
Oct 14, 20239.835NONO
CVE-2016-9841CRITICAL
inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
May 23, 20179.835NONO
CVE-2002-0059CRITICAL
The decompression algorithm in zlib 1.1.3 and earlier, as used in many different utilities and packages, causes inflateEnd to release certain memory more than once (a "double free"
Mar 15, 20029.835NONO
CVE-2026-22184HIGH
zlib versions up to and including 1.3.1.2 include a global buffer overflow in the untgz utility located under contrib/untgz. The vulnerability is limited to the standalone demonstr
Jan 7, 20267.834NONO
CVE-2016-9843CRITICAL
The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big-endian CRC calculation.
May 23, 20179.833NONO
CVE-2016-9842HIGH
The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers.
May 23, 20178.833NONO
CVE-2016-9840HIGH
inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
May 23, 20178.833NONO
View all 17 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products17 CVEs
24%
41%
29%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (5.9%)
Network10 (58.8%)
Unknown6 (35.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (64.7%)
High0 (0.0%)
Unknown6 (35.3%)
User Interaction
None9 (52.9%)
Unknown6 (35.3%)
Required2 (11.8%)
Privileges Required
Low1 (5.9%)
High0 (0.0%)
None10 (58.8%)
Unknown6 (35.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (17 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
5.9% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Zlib.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Zlib — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Zlib's Products

View all 6 CNAs →

Top CWEs