CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-40468

Critical · CVSS 9.1

gawk — Integer overflow leading to heap metadata overwrite / memory exhaustion

CVSS
9.1
nvd
EPSS
KEV
No
Class
other
CWE-190

Description

Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects gawk in versions 5.4.0 and below.

Search profile — drives PoC discovery

Symbols builtin.c062f2f2581b991362c046f7f2e238ffa34e6f8c7
Keywords CVE-2026-40468gawkinteger overflowbuiltin.cheap overflowCWE-190gawk 5.4.0memory exhaustionheap metadata overwrite
Versions: ≤ 5.4.0

References

Status: enriched · ingested 2026-07-14T06:00:21.000Z · profiled 2026-07-14T06:30:21.000Z