SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-40469

CRITICAL · CVSS 9.1 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-07-13 · Last synced 2026-08-12

CyberRota Analysis

AI-Generated

An integer overflow vulnerability in the do_sub() routine of the gawk program can lead to heap metadata and object corruption, resulting in crashes for affected systems. This critical flaw primarily impacts 32-bit builds of gawk versions 5.4.0 and earlier, making it essential for users and organizations relying on these versions for scripting and text processing to prioritize immediate updates or mitigations.

CVE
CVE-2026-40469
Severity
CRITICAL
CVSS
9.1
EPSS
0.21%

Original NVD Description

Integer overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine). This issue could be used to overwrite gawk heap metadata and objects causing the program to crash. It affects 32-bit builds of gawk in versions 5.4.0 and below.

Related CVEs

Other vulnerabilities affecting the same vendor(s)