This page lists publicly disclosed CVE vulnerabilities affecting zlib pigz (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2015-1191 | Multiple directory traversal vulnerabilities in pigz 2.3.1 allow remote attackers to write to arbitrary files via a (1) full pathname or (2) .. (dot dot) in an archive. | [email protected] | 5.0 | 3.03% | 2015-01-21 | 2026-05-06 |
| CVE-2013-0296 | Race condition in pigz before 2.2.5 uses permissions derived from the umask when compressing a file before setting that file's permissions to match those of the original file, which might allow local users to bypass intended access permissions while compression is occurring. | [email protected] | 4.4 | 0.34% | 2014-04-27 | 2026-05-06 |