SEPTEMBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-38752

LOW · CVSS 2.9 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-07-15 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

A stack overflow vulnerability in the evaluate() function of BusyBox can be exploited by attackers through specially crafted AWK scripts, leading to a Denial of Service (DoS) condition. While the severity is rated low, organizations using affected versions of BusyBox should prioritize patching to mitigate potential service disruptions. This is particularly relevant for environments where BusyBox is deployed in critical applications or services.

CVE
CVE-2026-38752
Severity
LOW
CVSS
2.9
EPSS
0.21%

Original NVD Description

A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.

Related CVEs

Other vulnerabilities affecting the same vendor(s)