{"id":"JLSEC-2026-478","details":"zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference).","modified":"2026-05-07T17:46:36.395570Z","published":"2026-05-07T17:36:47.122Z","upstream":["CVE-2022-37434"],"database_specific":{"sources":[{"id":"CVE-2022-37434","html_url":"https://nvd.nist.gov/vuln/detail/CVE-2022-37434","published":"2022-08-05T07:15:07.240Z","imported":"2026-05-07T17:21:38.963Z","modified":"2025-05-30T20:15:30.030Z","database_specific":{"status":"Modified"},"url":"https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2022-37434"}],"license":"CC-BY-4.0"},"references":[{"type":"WEB","url":"http://seclists.org/fulldisclosure/2022/Oct/37"},{"type":"WEB","url":"http://seclists.org/fulldisclosure/2022/Oct/37"},{"type":"WEB","url":"http://seclists.org/fulldisclosure/2022/Oct/38"},{"type":"WEB","url":"http://seclists.org/fulldisclosure/2022/Oct/38"},{"type":"WEB","url":"http://seclists.org/fulldisclosure/2022/Oct/41"},{"type":"WEB","url":"http://seclists.org/fulldisclosure/2022/Oct/41"},{"type":"WEB","url":"http://seclists.org/fulldisclosure/2022/Oct/42"},{"type":"WEB","url":"http://seclists.org/fulldisclosure/2022/Oct/42"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2022/08/05/2"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2022/08/05/2"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2022/08/09/1"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2022/08/09/1"},{"type":"WEB","url":"https://github.com/curl/curl/issues/9271"},{"type":"WEB","url":"https://github.com/curl/curl/issues/9271"},{"type":"WEB","url":"https://github.com/curl/curl/issues/9271"},{"type":"WEB","url":"https://github.com/ivd38/zlib_overflow"},{"type":"WEB","url":"https://github.com/ivd38/zlib_overflow"},{"type":"WEB","url":"https://github.com/madler/zlib/blob/21767c654d31d2dccdde4330529775c6c5fd5389/zlib.h#L1062-L1063"},{"type":"WEB","url":"https://github.com/madler/zlib/blob/21767c654d31d2dccdde4330529775c6c5fd5389/zlib.h#L1062-L1063"},{"type":"WEB","url":"https://github.com/madler/zlib/commit/1eb7682f845ac9e9bf9ae35bbfb3bad5dacbd91d"},{"type":"WEB","url":"https://github.com/madler/zlib/commit/eff308af425b67093bab25f80f1ae950166bece1"},{"type":"WEB","url":"https://github.com/madler/zlib/commit/eff308af425b67093bab25f80f1ae950166bece1"},{"type":"WEB","url":"https://github.com/nodejs/node/blob/75b68c6e4db515f76df73af476eccf382bbcb00a/deps/zlib/inflate.c#L762-L764"},{"type":"WEB","url":"https://github.com/nodejs/node/blob/75b68c6e4db515f76df73af476eccf382bbcb00a/deps/zlib/inflate.c#L762-L764"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2022/09/msg00012.html"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2022/09/msg00012.html"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JWN4VE3JQR4O2SOUS5TXNLANRPMHWV4I/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JWN4VE3JQR4O2SOUS5TXNLANRPMHWV4I/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NMBOJ77A7T7PQCARMDUK75TE6LLESZ3O/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NMBOJ77A7T7PQCARMDUK75TE6LLESZ3O/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PAVPQNCG3XRLCLNSQRM3KAN5ZFMVXVTY/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PAVPQNCG3XRLCLNSQRM3KAN5ZFMVXVTY/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X5U7OTKZSHY2I3ZFJSR2SHFHW72RKGDK/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X5U7OTKZSHY2I3ZFJSR2SHFHW72RKGDK/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YRQAI7H4M4RQZ2IWZUEEXECBE5D56BH2/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YRQAI7H4M4RQZ2IWZUEEXECBE5D56BH2/"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20220901-0005/"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20220901-0005/"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20230427-0007/"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20230427-0007/"},{"type":"WEB","url":"https://support.apple.com/kb/HT213488"},{"type":"WEB","url":"https://support.apple.com/kb/HT213488"},{"type":"WEB","url":"https://support.apple.com/kb/HT213489"},{"type":"WEB","url":"https://support.apple.com/kb/HT213489"},{"type":"WEB","url":"https://support.apple.com/kb/HT213490"},{"type":"WEB","url":"https://support.apple.com/kb/HT213490"},{"type":"WEB","url":"https://support.apple.com/kb/HT213491"},{"type":"WEB","url":"https://support.apple.com/kb/HT213491"},{"type":"WEB","url":"https://support.apple.com/kb/HT213493"},{"type":"WEB","url":"https://support.apple.com/kb/HT213493"},{"type":"WEB","url":"https://support.apple.com/kb/HT213494"},{"type":"WEB","url":"https://support.apple.com/kb/HT213494"},{"type":"WEB","url":"https://www.debian.org/security/2022/dsa-5218"},{"type":"WEB","url":"https://www.debian.org/security/2022/dsa-5218"}],"affected":[{"package":{"name":"GCCBootstrap_jll","ecosystem":"Julia","purl":"pkg:julia/GCCBootstrap_jll?uuid=7627cfbf-f290-59f7-b5e8-595c7b62b918"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"database_specific":{"source":"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-478.json"}},{"package":{"name":"Openresty_jll","ecosystem":"Julia","purl":"pkg:julia/Openresty_jll?uuid=87da34d4-7b1b-5a94-8376-8cb65bf3132c"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.27.1+0"}]}],"database_specific":{"source":"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-478.json"}},{"package":{"name":"Zlib_jll","ecosystem":"Julia","purl":"pkg:julia/Zlib_jll?uuid=83775a58-1f1d-513f-b197-d71354ab007a"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.2.13+0"}]}],"database_specific":{"source":"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-478.json"}}],"schema_version":"1.7.5"}