{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3hnetapphci_compute_node-/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:zlib:zlib:*:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*","cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*","cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:*","cpe:2.3:a:netapp:hci:-:*:*:*:*:*:*:*","cpe:2.3:a:netapp:management_services_for_element_software:-:*:*:*:*:*:*:*","cpe:2.3:a:netapp:oncommand_workflow_automation:-:*:*:*:*:*:*:*","cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:*","cpe:2.3:a:netapp:storagegrid:-:*:*:*:*:*:*:*","cpe:2.3:h:netapp:hci_compute_node:-:*:*:*:*:*:*:*","cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*","cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*","cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*","cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*","cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*","cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*","cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2022-37434"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["zlib"],"_cs_severities":["medium"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe zlib compression library is affected by a heap-based buffer overflow vulnerability, identified as CVE-2022-37434. This vulnerability resides in the way the library handles specifically crafted inputs during decompression operations. A remote, unauthenticated attacker can exploit this flaw by providing malicious compressed data to an application that utilizes a vulnerable version of zlib. Successful exploitation leads to arbitrary code execution within the context of the application or a denial of service (DoS) through application crashing. Given that zlib is a foundational component used across a wide range of software, operating systems, and network devices, the attack surface is broad, requiring security teams to verify their dependency trees for vulnerable library versions.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for unauthorized code execution with the privileges of the targeted application, potentially leading to full system compromise or service disruption. The impact is significant due to the library's ubiquity in both enterprise and embedded software ecosystems.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eIdentify and update all software dependencies that incorporate the zlib library to a patched version. Monitor build pipelines and vulnerability management scanners for CVE-2022-37434 to locate vulnerable library instances.\u003c/p\u003e\n","date_modified":"2026-08-21T13:14:31Z","date_published":"2026-08-21T13:14:31Z","id":"https://feed.craftedsignal.io/briefs/2026-08-zlib-vulnerability/","summary":"A memory corruption vulnerability in the zlib library allows a remote, unauthenticated attacker to execute arbitrary code or trigger a denial of service.","title":"Remote Code Execution Vulnerability in zlib","url":"https://feed.craftedsignal.io/briefs/2026-08-zlib-vulnerability/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:h:netapp:hci_compute_node:-:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}