[UPDATE] [medium] gzip: Multiple vulnerabilities
A local attacker can exploit multiple vulnerabilities in gzip to manipulate files and disclose confidential information.
CSIRTS triage
- What
- Multiple vulnerabilities allow a local attacker to manipulate files and disclose confidential information.
- Who is affected
- Local attackers exploiting vulnerabilities in gzip.
- Urgency
- Remediation is medium urgency due to the potential for information disclosure.
- Action
- Update to the latest version of gzip.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch gzip
Get an email when a new gzip advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2126
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-419910.12% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-419920.35% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-41991 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-41992 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownUSN-8512-1: Gzip vulnerabilitiesubuntu
- highCVE-2026-41992: GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused…nvd
- mediumCVE-2026-41991: GNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file hand…nvd
- unknownCVE-2026-41991: Predictable Temporary File in GNU gzipmsrc
- unknownCVE-2026-41992: Global Buffer Overflow in GNU gzipmsrc
Recent advisories for gzip
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highGHSA-6ccx-9c9f-327w: gRPC Erlang package has unbounded gzip decompression (decompression bomb)ghsa · 2026-08-25
- mediumCVE-2026-77639: Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate …nvd · 2026-08-20
- highCVE-2026-75936: Improper handling of highly compressed data in the GZIP auto-decompression handler in Amazon i…nvd · 2026-08-18
- highGHSA-g4w2-6h2r-3m3w: http4k: Unbounded gzip decompression in `ServerFilters.GZip` / `RequestFilters.GunZip` al…ghsa · 2026-08-17
- highCVE-2026-68981: Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST A…nvd · 2026-08-03
- unknownCVE-2026-66913: Lookyloo did not enforce limits on the decompressed size of uploaded capture archives and comp…nvd · 2026-07-28
More from CERT-Bund (BSI) Security Advisories
- high[NEW] [high] Linux Kernel: Multiple vulnerabilities2026-08-25
- medium[NEW] [medium] libTIFF: Multiple Vulnerabilities2026-08-25
- high[NEW] [high] Contao: Multiple Vulnerabilities2026-08-25
- medium[NEW] [medium] Django: Multiple Vulnerabilities2026-08-25
- high[NEW] [high] Red Hat Enterprise Linux (Apicurio Registry): Multiple Vulnerabilities2026-08-25