LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-40468

fossies · gawk

Published
CVSS9.1
Severitycritical
WeaknessCWE-190
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Description

Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects gawk in versions 5.4.0 and below.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-40468

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-40468.