Skip to content
COOEY

EXPOSURES › CVE-2026-40469

CVE-2026-40469

CRITICAL
DETAIL
SourceNVD · cve Published2026-07-13 CVSS9.1 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-40469 ↗
SHAME 35/100

Integer overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine). This issue could be used to overwrite gawk heap metadata and objects causing the program to crash. It affects 32-bit builds of gawk in versions 5.4.0 and below.

▸ RECOMMENDED ACTION  Critical severity — schedule patching of the affected products.

DESCRIPTION

Integer overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine). This issue could be used to overwrite gawk heap metadata and objects causing the program to crash. It affects 32-bit builds of gawk in versions 5.4.0 and below.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.