VDB
CVE-2026-40553
CVE-2026-40553
PUBLISHED
CVSS 5.1 MEDIUM
Reported by CERT-PL · Published July 13, 2026
Buffer overflow vulnerability has been found in "extension/readdir.c" program file of gawk (ftype() routine). This issue could be used to crash the program and potentially to achieve code execution, although the latter has not been confirmed to be feasible. It affects gawk in versions 5.4.0 and below.
Risk Scores
CVSS 4.0
5.1
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:L/SI:L/SA:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| GNU | gawk | 0 |
| GNU | gawk | 0 |
Timeline
- Jul 13, 2026 Coalition ESS Score
- Jul 13, 2026 CVE Published
- Jul 13, 2026 CVE Updated
- Aug 7, 2026 EPSS Score