SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-40468

CRITICAL · CVSS 9.1 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-07-13 · Last synced 2026-08-12

CyberRota Analysis

AI-Generated

An integer overflow vulnerability in the "builtin.c" file of gawk versions 5.4.0 and below allows attackers to exploit memory exhaustion on the host operating system, potentially leading to the overwriting of gawk heap metadata and objects with malicious data. This critical flaw poses significant risks to systems running affected versions, and organizations utilizing gawk should prioritize immediate updates to mitigate potential exploitation.

CVE
CVE-2026-40468
Severity
CRITICAL
CVSS
9.1
EPSS
0.20%

Original NVD Description

Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects gawk in versions 5.4.0 and below.

Related CVEs

Other vulnerabilities affecting the same vendor(s)