CVE-2026-27171
Low
CVE-2026-27171
zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.
Exploit probability
0.2%
Published
February 18, 2026
Required by
Not available
Last source change
August 12, 2026
02 / AFFECTED SOFTWARE
Affected packages
5 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
CVE-2026-27171
View original source
zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.
05 / REFERENCES
Further evidence
- https://7asecurity.com/blog/2026/02/zlib-7asecurity-audit/
- https://7asecurity.com/reports/pentest-report-zlib-RC1.1.pdf
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/27xxx/CVE-2026-27171.json
- https://github.com/madler/zlib/issues/904
- https://github.com/madler/zlib/releases/tag/v1.3.2
- https://nvd.nist.gov/vuln/detail/CVE-2026-27171
- https://ostif.org/zlib-audit-complete/