CVE-2019-13636: GNU Patch
Medium severity, CVSS 5.9. EPSS: 3.9% chance of exploitation in the next 30 days.
In GNU patch through 2.7.6, the following of symlinks is mishandled in certain cases other than input files. This affects inp.c and util.c.
Affected products
- GNU Patch: up to and including 2.7.6
Published 2019-07-17. Last modified 2026-06-17.