Known Vulnerabilities for Gzip by Gnu
Listed below are 10 of the newest known vulnerabilities associated with "Gzip" by "Gnu".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-40324 json | Hot Chocolate is an open-source GraphQL server. Prior to versions 12.22.7, 13.9.16, 14.3.1, and 15.1.14, Hot Chocolate's recu... | Not Provided | 2026-04-18 | 2026-04-20 |
| CVE-2026-40192 json | Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when... | Not Provided | 2026-04-15 | 2026-04-16 |
| CVE-2026-39414 json | MinIO is a high-performance object storage system. From RELEASE.2018-08-18T03-49-57Z to before RELEASE.2025-12-20T04-58-37Z, ... | Not Provided | 2026-04-08 | 2026-04-09 |
| CVE-2026-35465 json | SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle submissions on the SecureD... | Not Provided | 2026-04-18 | 2026-04-20 |
| CVE-2026-6100 json | Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memory al... | Not Provided | 2026-04-13 | 2026-04-14 |
| CVE-2026-5438 json | A gzip decompression bomb vulnerability exists when Orthanc processes HTTP request with `Content-Encoding: gzip`. The server ... | Not Provided | 2026-04-09 | 2026-04-14 |
| CVE-2022-1271 json | An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen f... | 8.8 - HIGH | 2022-08-31 | 2023-11-07 |
| CVE-2010-0001 json | Integer underflow in the unlzw function in unlzw.c in gzip before 1.4 on 64-bit platforms, as used in ncompress and probably ... | 6.8 - MEDIUM | 2010-01-29 | 2023-02-13 |
| CVE-2009-2624 json | The huft_build function in inflate.c in gzip before 1.3.13 creates a hufts (aka huffman) table that is too small, which allow... | 6.8 - MEDIUM | 2010-01-29 | 2010-11-18 |
| CVE-2005-1228 json | Not Provided | 2005-05-02 | 2025-04-03 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Gnu | Gzip | 1.9 | |||
| Application | Gnu | Gzip | 1.8 | |||
| Application | Gnu | Gzip | 1.7 | |||
| Application | Gnu | Gzip | 1.6 | |||
| Application | Gnu | Gzip | 1.5 | |||
| Application | Gnu | Gzip | 1.4 | |||
| Application | Gnu | Gzip | 1.3.9 | |||
| Application | Gnu | Gzip | 1.3.8 | |||
| Application | Gnu | Gzip | 1.3.7 | |||
| Application | Gnu | Gzip | 1.3.6 | |||
| Application | Gnu | Gzip | 1.3.5 | |||
| Application | Gnu | Gzip | 1.3.4 | |||
| Application | Gnu | Gzip | 1.3.3 | |||
| Application | Gnu | Gzip | 1.3.14 | |||
| Application | Gnu | Gzip | 1.3.13 | |||
| Application | Gnu | Gzip | 1.3.12 | |||
| Application | Gnu | Gzip | 1.3.11 | |||
| Application | Gnu | Gzip | 1.3.10 | |||
| Application | Gnu | Gzip | 1.3 | |||
| Application | Gnu | Gzip | 1.2.4a |