CVE-2026-40469
published 2026-07-13CVE-2026-40469: Integer overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine). This issue could be used to overwrite gawk heap metadata…
PriorityP350critical9.1CVSS 3.1
AVNACLPRNUINSUCNIHAH
EPSS
0.21%
11.6th percentile
Integer overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine). This issue could be used to overwrite gawk heap metadata and objects causing the program to crash. It affects 32-bit builds of gawk in versions 5.4.0 and below.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fossies | gawk | <= 5.4.0 | — |
| gnu | gawk | <= 5.4.0 | — |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
nvdv4.05.1MEDIUMCVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
GNU gawk up to 5.4.0 builtin.c do_sub integer overflow (Nessus ID 326562)
vuldb·2026-07-14·CVSS 9.1
CVE-2026-40469 [CRITICAL] GNU gawk up to 5.4.0 builtin.c do_sub integer overflow (Nessus ID 326562)
A vulnerability, which was classified as problematic, has been found in GNU gawk up to 5.4.0. The impacted element is the function do_sub of the file builtin.c. Performing a manipulation results in integer overflow.
This vulnerability is cataloged as CVE-2026-40469. The attack must be initiated from a local position. There is no exploit available.
GHSA
Integer overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine).
ghsa_unreviewed·2026-07-13
CVE-2026-40469 [MEDIUM] CWE-190 Integer overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine).
Integer overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine). This issue could be used to overwrite gawk heap metadata and objects causing the program to crash. It affects 32-bit builds of gawk in versions 5.4.0 and below.
No detection rules found.
No public exploits indexed.
Rapid7
Patch Tuesday - July 2026
blogs_rapid7·2026-07-14·CVSS 9.6
CVE-2026-58617 [CRITICAL] Patch Tuesday - July 2026
Microsoft is publishing 622 vulnerabilities on July 2026 Patch Tuesday , including a record-breaking 416 Windows vulnerabilities. Microsoft is aware of exploitation in the wild for two of the vulnerabilities published today, both of which are listed on CISA KEV, as well as public disclosure for one other. As usual, browser vulns are not included in the Patch Tuesday count above. Rapid7 noted last month that Microsoft no longer enumerates Chromium CVEs in the Security Update Guide. However, Microsoft has now taken the pursuit of minimalism much further, since today’s Security Update Guide no longer lists out even Microsoft vulnerabilities! Instead, we now receive a summary table of vulnerability counts by product family, as well as a new slimline “Notable CVEs” section. All of this only ser
Bugzilla
CVE-2026-40469 gawk: gawk: Denial of Service due to integer overflow
bugzilla·2026-07-13·CVSS 9.1
CVE-2026-40469 [CRITICAL] CVE-2026-40469 gawk: gawk: Denial of Service due to integer overflow
CVE-2026-40469 gawk: gawk: Denial of Service due to integer overflow
Integer overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine). This issue could be used to overwrite gawk heap metadata and objects causing the program to crash. It affects 32-bit builds of gawk in versions 5.4.0 and below.
2026-07-13
Published