CVE detail
CVE-2026-22184
zlib versions up to and including 1.3.1.2 include a global buffer overflow in the untgz utility located under contrib/untgz. The vulnerability is limited to the standalone demonstration utility and does not affect the core zlib compression library. The flaw occurs when a user executes the untgz command with an excessively long archive name supplied via the command line, leading to an out-of-bounds write in a fixed-size global buffer.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 24.0 · diversity 20.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 1
- within the 30d window
- Peak daily
- 1
- highest bucket
Evidence
Source links by recency
10 source links · newest first
- Siemens CADRACISA Alerts
cations, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2005-2096 zlib 1.2 and later versions allows remote attackers to cause a denial of service (crash) via a crafted compressed stream with an incomplete code description of a length greater than 1, which leads to a buffer overflow,
governmentwww.cisa.govJul 21, 2026, 12:00 PM - https://cert-portal.siemens.com/productcert/html/ssa-470355.htmlcert-portal.siemens.com
No excerpt available.
Vendor Advisorycert-portal.siemens.comJan 7, 2026, 9:16 PM - https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-22184.jsonsecurity.access.redhat.com
No excerpt available.
Vendor Advisorysecurity.access.redhat.comJan 7, 2026, 9:16 PM - https://bugzilla.redhat.com/show_bug.cgi?id=2427688bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comJan 7, 2026, 9:16 PM - https://access.redhat.com/security/cve/CVE-2026-22184access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJan 7, 2026, 9:16 PM No excerpt available.
Exploitgithub.comJan 7, 2026, 9:16 PM- https://zlib.net/zlib.net
No excerpt available.
Productzlib.netJan 7, 2026, 9:16 PM No excerpt available.
Exploitwww.vulncheck.comJan 7, 2026, 9:16 PM- https://seclists.org/fulldisclosure/2026/Jan/3seclists.org
No excerpt available.
Exploitseclists.orgJan 7, 2026, 9:16 PM - https://github.com/madler/zlibgithub.com
No excerpt available.
Exploitgithub.comJan 7, 2026, 9:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2022-37434CVSS 9.8 · Critical
zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetH…
- CVE-2026-59250CVSS 8.3 · High
Classic buffer overflow in the Erlang/OTP megaco flex scanner C driver allows a remote unauthenticated attacker to corrupt the driver's memory (and potentially achieve remote code…
- CVE-2026-44436CVSS 7.5 · High
Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit 8b178e6, Quicly is vulnerable to a Denial of Service attack t…
- CVE-2026-6681CVSS 1.0 · Low
The PKCS#7 decode path ignores the caller-supplied output buffer size (outputSz), allowing decoded content to be written past the bounds of the provided buffer. This affects wolfS…
- CVE-2026-53203CVSS 7.1 · High
In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Add buffer overflow check in MS get_info_ioctl Add validation that the info size returned from th…
- CVE-2026-0164CVSS 8.8 · High
In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User inte…