SEPTEMBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-38755

LOW · CVSS 2.9 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-07-15 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

A heap overflow vulnerability in the evalcommand() function of Busybox v1.38.0 can be exploited by attackers to trigger a Denial of Service (DoS) by providing specially crafted input. While the CVSS score is low, organizations using this version of Busybox should prioritize patching to mitigate potential service disruptions. Users of affected products should assess their exposure and apply necessary updates to maintain system stability.

CVE
CVE-2026-38755
Severity
LOW
CVSS
2.9
EPSS
0.21%

Original NVD Description

A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.

Related CVEs

Other vulnerabilities affecting the same vendor(s)