CVE-2026-40553: Fossies Gawk

High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Buffer overflow vulnerability has been found in "extension/readdir.c" program file of gawk (ftype() routine). This issue could be used to crash the program and potentially to achieve code execution, although the latter has not been confirmed to be feasible. It affects gawk in versions 5.4.0 and below.

Affected products

  • Fossies Gawk: up to and including 5.4.0

Published 2026-07-13. Last modified 2026-07-14.