VDB

CVE-2026-40468

CVE-2026-40468 PUBLISHED CVSS 2.1 LOW

Reported by CERT-PL · Published July 13, 2026

Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects gawk in versions 5.4.0 and below.

Risk Scores

CVSS 4.0
2.1
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:L

Affected Products

VendorProductVersions
GNUgawk0
GNUgawk0

Timeline

  • Jul 13, 2026 Coalition ESS Score
  • Jul 13, 2026 CVE Published
  • Jul 14, 2026 CVE Updated
  • Aug 7, 2026 EPSS Score
  • Aug 24, 2026 EPSS Score

References

  • patch
  • third-party-advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›