Skip to content
COOEY

EXPOSURES › CVE-2026-40468

CVE-2026-40468

CRITICAL
DETAIL
SourceNVD · cve Published2026-07-13 CVSS9.1 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-40468 ↗
SHAME 35/100

Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects gawk in versions 5.

▸ RECOMMENDED ACTION  Critical severity — schedule patching of the affected products.

DESCRIPTION

Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects gawk in versions 5.4.0 and below.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.