VDB
CVE-2026-40468
CVE-2026-40468
PUBLISHED
CVSS 2.1 LOW
Reported by CERT-PL · Published July 13, 2026
Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects gawk in versions 5.4.0 and below.
Risk Scores
CVSS 4.0
2.1
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| GNU | gawk | 0 |
| GNU | gawk | 0 |
Timeline
- Jul 13, 2026 Coalition ESS Score
- Jul 13, 2026 CVE Published
- Jul 14, 2026 CVE Updated
- Aug 7, 2026 EPSS Score
- Aug 24, 2026 EPSS Score