CVE-2026-40553Disclosure(fossies / gawk)

LOWCVSS 7.5 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Buffer overflow vulnerability has been found in "extension/readdir.c" program file of gawk (ftype() routine). This issue could be used to crash the program and potentially to achieve code execution, although the latter has not been confirmed to be feasible. It affects gawk in versions 5.4.0 and below.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-121

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gawk

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Disclouser: 1 classified signal
  • Peaked at 3 mentions on most recent observed day (2026-07-13)
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
gawk

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-02-03: 1Mentions · 2026-07-13: 3Technical Details · 2026-07-13: 302-0307-13
Signal classification3 categories
Disclosure
250.0%
General
125.0%
Disclouser
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-031
General1
2026-07-133
Disclosure2Disclouser1
Full discourse4 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-40553 Buffer Overflow in Gawk Extension Readdir.c ftype() Routine Versions 5.4.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40553

    Post summary

    A buffer overflow vulnerability (CVE-2026-40553) in Gawk 5.4.0’s readdir.c ftype() routine has been disclosed, with no PoC, exploit, or active exploitation reported.

    00000123
    4.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-40553 Buffer overflow vulnerability has been found in "extension/readdir.c" program file of gawk (ftype() routine). This issue could be used to crash the program and potent… https://www.cve.org/CVERecord?id=CVE-2026-40553 ----- Traducción: La vulnerabilidad … http://infoflow.cloud`

    Post summary

    A buffer overflow vulnerability (CVE-2026-40553) has been identified in gawk’s readdir.c file, potentially allowing attackers to crash the program.

    0000043
    92 followersView on X
  • CVE@CVEnew
    Disclouser

    CVE-2026-40553 Buffer overflow vulnerability has been found in "extension/readdir.c" program file of gawk (ftype() routine). This issue could be used to crash the program and potent… https://www.cve.org/CVERecord?id=CVE-2026-40553

    Post summary

    The CVE-2026-40553 disclosure describes a buffer overflow in gawk’s ftype() routine that could crash the program; no exploit, patch, or active exploitation details are provided.

    00000644
    57.8K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos SolarWinds ❗ CVE-2026-40553 ❗ CVE-2026-40552 ❗ CVE-2026-40551 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-solarwinds-2/ https://t.co/8n5ZbLdRdU

    Post summary

    The post lists three CVE identifiers for SolarWinds products and links to external resources for further details.

    00000104
    6.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfossiesgawk---

Explore more