CVE Explorer
CVE-2026-27820
zlib is a Ruby interface for the zlib compression/decompression library. Versions 3.0.0 and below, 3.1.0, 3.1.1, 3.2.0 and 3.2.1 contain a buffer overflow vulnerability in the Zlib::GzipReader. The zstream_buffer_ungets function prepends caller-provided bytes ahead of previously produced output but fails to guarantee the backing Ruby string has enough capacity before the memmove shifts the existing data. This can lead to memory corruption when the buffer length exceeds capacity. This issue has b
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-131","description":"CWE-131: Incorrect Calculation of Buffer Size","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:8aa521b159c2846baeaaa89b6678a33b60a5605d7ca6d012390e6a3333893050 · sha256:93eba853633b98a3… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-120","description":"CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:8aa521b159c2846baeaaa89b6678a33b60a5605d7ca6d012390e6a3333893050 · sha256:93eba853633b98a3… · /containers/cna/problemTypes/0/descriptions/0
Affected products and versions
1 source assertion{"product":"zlib","vendor":"ruby","versions":[{"status":"affected","version":"< 3.0.1"},{"status":"affected","version":">= 3.1.0, < 3.1.2"},{"status":"affected","version":">= 3.2.0, < 3.2.3"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:8aa521b159c2846baeaaa89b6678a33b60a5605d7ca6d012390e6a3333893050 · sha256:93eba853633b98a3… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"NETWORK","baseScore":1.7,"baseSeverity":"LOW","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U","version":"4.0","vulnAvailabilityImpact":"LOW","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:8aa521b159c2846baeaaa89b6678a33b60a5605d7ca6d012390e6a3333893050 · sha256:93eba853633b98a3… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
2 source assertions{"cweId":"CWE-131","description":"CWE-131: Incorrect Calculation of Buffer Size","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:8aa521b159c2846baeaaa89b6678a33b60a5605d7ca6d012390e6a3333893050 · sha256:93eba853633b98a3… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-120","description":"CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:8aa521b159c2846baeaaa89b6678a33b60a5605d7ca6d012390e6a3333893050 · sha256:93eba853633b98a3… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/ruby/zlib/security/advisories/GHSA-g857-hhfv-j68w","tags":["x_refsource_CONFIRM"],"url":"https://github.com/ruby/zlib/security/advisories/GHSA-g857-hhfv-j68w"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:8aa521b159c2846baeaaa89b6678a33b60a5605d7ca6d012390e6a3333893050 · sha256:93eba853633b98a3… · /containers/cna/references/0
{"name":"https://hackerone.com/reports/3467067","tags":["x_refsource_MISC"],"url":"https://hackerone.com/reports/3467067"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:8aa521b159c2846baeaaa89b6678a33b60a5605d7ca6d012390e6a3333893050 · sha256:93eba853633b98a3… · /containers/cna/references/1
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.