SEPTEMBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-38753

MEDIUM · CVSS 4.9 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-07-15 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

A use-after-free vulnerability in the awk_sub() function of Busybox v1.38.0 can be exploited by attackers through specially crafted AWK scripts, leading to a Denial of Service (DoS). Organizations using this version of Busybox should prioritize patching to mitigate potential disruptions caused by this vulnerability.

CVE
CVE-2026-38753
Severity
MEDIUM
CVSS
4.9
EPSS
0.14%

Original NVD Description

A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.

Related CVEs

Other vulnerabilities affecting the same vendor(s)