Post #2049067
2026-01-18 14:10 UTC
Fun, another "critical severity" (9.3 CVSS score) CVE for zlib that only affects a reference program that's not shipped.
The CVE in the meantime has been adjusted with a lower score, but too late for the security scanners to start reporting and us receiving reports like:
> we found a CRITICAL CVE in the OS level
#AlpineSecurity
Replies (1)
-
@ikke@ipv6.social 2026-01-18 14:11
Upstream reference: https://github.com/madler/zlib/issues/1142