Technology · Gnome
Gnome GLib vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 18 vulnerabilities in Gnome GLib: 0 in the last 7 days and 8 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-15588, was published on 20 July 2026.
- Last 7 days
- 0
- Last 90 days
- 8
- Critical, all time
- 0
- Exploited in the wild
- 0
About Gnome GLib
A general-purpose utility library, which provides many low-level data types, variants, and software tool types for C programs.
Latest Gnome GLib vulnerabilities
- CVE-2026-15588: GNOME GLib denial of service in GDBus authenticationmediumCVSS 5.3
- CVE-2026-58016: GNOME GLib out-of-bounds read in D-Bus introspection XML parsinghighCVSS 7.5
- CVE-2026-58015: GLib path traversal in GDBus DBUS_COOKIE_SHA1 authenticationmediumCVSS 5.9
- CVE-2026-58014: GNOME GLib off-by-one error in g_key_file_get_locale_string_listhighCVSS 7.3
- CVE-2026-58013: GNOME GLib buffer over-read in g_io_channel_read_line_backendmediumCVSS 6.5
- CVE-2026-58012: GNOME GLib buffer over-read in g_regex_replacemediumCVSS 6.5
- CVE-2026-58011: GNOME GLib out-of-bounds read in g_date_time_get_ymdmediumCVSS 6.5
- CVE-2026-58010: GLib off-by-one error in GVariant serializermediumCVSS 6.5
- CVE-2026-1489: GNOME GLib integer overflow in Unicode case conversionmediumCVSS 5.4EPSS 0.0%
- CVE-2026-1484: GNOME GLib integer overflow in Base64 encodingmediumCVSS 4.2EPSS 0.0%
- CVE-2025-14512: GNOME GLib heap buffer overflow in GIO escape_byte_stringmediumCVSS 6.5EPSS 0.1%
- CVE-2025-14087: GNOME GLib heap corruption in GVariant parsermediumCVSS 5.6EPSS 0.1%
- CVE-2025-13601: GNOME GLib heap buffer overflow in g_escape_uri_stringhighCVSS 7.7EPSS 0.0%
- CVE-2025-7039: GLib integer overflow in temporary file creationlowCVSS 3.7EPSS 0.1%
- CVE-2025-4056: GNOME GLib integer overflow in gspawn-win32.chighCVSS 7.5EPSS 0.4%
- CVE-2025-6052: GNOME GLib integer overflow in g_string_maybe_expandlowCVSS 3.7EPSS 0.3%
- CVE-2025-4373: GNOME GLib integer overflow in g_string_insert_unicharmediumCVSS 4.8
- CVE-2024-34397: GNOME GLib spoofing vulnerability in GDBus signal subscriptionsmediumCVSS 5.2
Most severe Gnome GLib vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2025-13601: GNOME GLib heap buffer overflow in g_escape_uri_stringhighCVSS 7.7EPSS 0.0%
- CVE-2025-4056: GNOME GLib integer overflow in gspawn-win32.chighCVSS 7.5EPSS 0.4%
- CVE-2026-58016: GNOME GLib out-of-bounds read in D-Bus introspection XML parsinghighCVSS 7.5
- CVE-2026-58014: GNOME GLib off-by-one error in g_key_file_get_locale_string_listhighCVSS 7.3
- CVE-2025-14512: GNOME GLib heap buffer overflow in GIO escape_byte_stringmediumCVSS 6.5EPSS 0.1%
- CVE-2026-58013: GNOME GLib buffer over-read in g_io_channel_read_line_backendmediumCVSS 6.5
- CVE-2026-58012: GNOME GLib buffer over-read in g_regex_replacemediumCVSS 6.5
- CVE-2026-58011: GNOME GLib out-of-bounds read in g_date_time_get_ymdmediumCVSS 6.5
- CVE-2026-58010: GLib off-by-one error in GVariant serializermediumCVSS 6.5
- CVE-2026-58015: GLib path traversal in GDBus DBUS_COOKIE_SHA1 authenticationmediumCVSS 5.9
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 7 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 1 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/glib.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Gnome GLib vulnerabilities", https://junglewise.ai/threats/technologies/glib, 26 September 2026.