Gnu Gawk vulnerabilities
5 known vulnerabilities affecting gnu/gawk.
Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH3
Vulnerabilities
Page 1 of 1
CVE-2026-40468P3CRITICALCVSS 9.1≤ 5.4.02026-07-13
CVE-2026-40468 [CRITICAL] CWE-190 CVE-2026-40468: Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may le
Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects gawk in versions 5.4.0 and below.
nvd
CVE-2026-40469P3CRITICALCVSS 9.1≤ 5.4.02026-07-13
CVE-2026-40469 [CRITICAL] CWE-190 CVE-2026-40469: Integer overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine)
Integer overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine). This issue could be used to overwrite gawk heap metadata and objects causing the program to crash. It affects 32-bit builds of gawk in versions 5.4.0 and below.
nvd
CVE-2026-40553P3HIGHCVSS 7.5≤ 5.4.02026-07-13
CVE-2026-40553 [HIGH] CWE-121 CVE-2026-40553: Buffer overflow vulnerability has been found in "extension/readdir.c" program file of gawk (ftype()
Buffer overflow vulnerability has been found in "extension/readdir.c" program file of gawk (ftype() routine). This issue could be used to crash the program and potentially to achieve code execution, although the latter has not been confirmed to be feasible. It affects gawk in versions 5.4.0 and below.
nvd
CVE-2026-40467P3HIGHCVSS 7.5≤ 5.4.02026-07-13
CVE-2026-40467 [HIGH] CWE-416 CVE-2026-40467: Use After Free vulnerability has been found in "io.c" program file of gawk (do_getline_redir() routi
Use After Free vulnerability has been found in "io.c" program file of gawk (do_getline_redir() routine). This issue may lead to a crash. It affects gawk in versions 5.4.0 and below.
nvd
CVE-2023-4156P4HIGHCVSS 7.1fixed in 5.1.12023-09-25
CVE-2023-4156 [HIGH] CWE-125 CVE-2023-4156: A heap out-of-bounds read flaw was found in builtin.c in the gawk package. This issue may lead to a
A heap out-of-bounds read flaw was found in builtin.c in the gawk package. This issue may lead to a crash and could be used to read sensitive information.
nvdosv