{"schema_version":1,"title":"Gnu vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 142 vulnerabilities in Gnu: 6 in the last 7 days and 63 in the last 90 days, 7 of them critical and 5 exploited in the wild. The most recent, CVE-2026-100310, was published on 25 September 2026. 14 technologies have a page of their own.","url":"https://junglewise.ai/threats/vendors/gnu","json_url":"https://junglewise.ai/threats/vendors/gnu.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/gnu","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":30,"all_time":142,"critical":7,"exploited":5,"last_7_days":6,"last_30_days":28,"last_90_days":63,"last_365_days":110},"latest":[{"cve":"CVE-2026-100310","cvss":7,"slug":"cve-2026-100310-gnu-libextractor-before-1-16-loads-plugins-from-an-untrusted","title":"GNU libextractor privilege escalation via plugin search path","severity":"high","exploited":false,"published_at":"2026-09-25T20:17:05.833+00:00","url":"https://junglewise.ai/threats/cve-2026-100310-gnu-libextractor-before-1-16-loads-plugins-from-an-untrusted"},{"cve":"CVE-2026-96442","cvss":7.8,"epss":0.0017,"slug":"cve-2026-96442-a-code-execution-flaw-was-found-in-emacs-affecting-versions-prior","title":"Emacs Flymake code execution via untrusted files","severity":"high","exploited":false,"published_at":"2026-09-23T11:17:18.55+00:00","url":"https://junglewise.ai/threats/cve-2026-96442-a-code-execution-flaw-was-found-in-emacs-affecting-versions-prior"},{"cve":"CVE-2026-96269","epss":0.0015,"slug":"cve-2026-96269-gnu-emacs-28-1-through-31-1-allows-arbitrary-code-execution-upon","title":"GNU Emacs arbitrary code execution in symbol handling","severity":"info","exploited":false,"published_at":"2026-09-22T21:17:35.15+00:00","url":"https://junglewise.ai/threats/cve-2026-96269-gnu-emacs-28-1-through-31-1-allows-arbitrary-code-execution-upon"},{"cve":"CVE-2026-94574","cvss":7.8,"epss":0.0012,"slug":"cve-2026-94574-a-local-cross-user-code-execution-vulnerability-exists-in-gnu","title":"GNU wget local code execution via hardcoded config path","severity":"high","exploited":false,"published_at":"2026-09-22T20:17:13.24+00:00","url":"https://junglewise.ai/threats/cve-2026-94574-a-local-cross-user-code-execution-vulnerability-exists-in-gnu"},{"cve":"CVE-2026-86805","cvss":6.3,"epss":0.0012,"slug":"cve-2026-86805-a-time-of-check-to-time-of-use-toctou-race-condition-in-the","title":"GNU C Library dynamic loader privilege escalation via TOCTOU race","severity":"medium","exploited":false,"published_at":"2026-09-22T16:18:06.23+00:00","url":"https://junglewise.ai/threats/cve-2026-86805-a-time-of-check-to-time-of-use-toctou-race-condition-in-the"},{"cve":"CVE-2026-95619","cvss":7.7,"epss":0.0036,"slug":"cve-2026-95619-a-flaw-was-found-in-libstdc-an-integer-overflow-can-occur-when","title":"libstdc++ integer overflow in aligned operator new","severity":"high","exploited":false,"published_at":"2026-09-22T13:17:13.3+00:00","url":"https://junglewise.ai/threats/cve-2026-95619-a-flaw-was-found-in-libstdc-an-integer-overflow-can-occur-when"},{"cve":"CVE-2026-8674","cvss":5.3,"epss":0.0034,"slug":"cve-2026-8674-gnu-c-library-dns-resolver-assertion-failure-in-search-list","title":"GNU C Library DNS resolver assertion failure in search list parsing","severity":"medium","exploited":false,"published_at":"2026-09-17T17:16:53.22+00:00","url":"https://junglewise.ai/threats/cve-2026-8674-gnu-c-library-dns-resolver-assertion-failure-in-search-list"},{"cve":"CVE-2026-80489","cvss":5.9,"epss":0.0041,"slug":"cve-2026-80489-gnu-c-library-euc-jisx0213-converter-denial-of-service","title":"GNU C Library EUC_JISX0213 converter denial of service","severity":"medium","exploited":false,"published_at":"2026-09-15T11:17:12.193+00:00","url":"https://junglewise.ai/threats/cve-2026-80489-gnu-c-library-euc-jisx0213-converter-denial-of-service"},{"cve":"CVE-2026-77117","cvss":5.9,"epss":0.0041,"slug":"cve-2026-77117-gnu-c-library-shift-jisx0213-converter-hang-in-iconv","title":"GNU C Library SHIFT_JISX0213 converter hang in iconv","severity":"medium","exploited":false,"published_at":"2026-09-15T11:17:12.063+00:00","url":"https://junglewise.ai/threats/cve-2026-77117-gnu-c-library-shift-jisx0213-converter-hang-in-iconv"},{"cve":"CVE-2026-91782","cvss":3.3,"epss":0.0018,"slug":"cve-2026-91782-gnu-binutils-null-pointer-dereference-in-dynamic-relocation","title":"GNU Binutils null pointer dereference in dynamic relocation allocation","severity":"low","exploited":false,"published_at":"2026-09-15T09:16:45.35+00:00","url":"https://junglewise.ai/threats/cve-2026-91782-gnu-binutils-null-pointer-dereference-in-dynamic-relocation"},{"cve":"CVE-2026-91781","cvss":3.3,"epss":0.0018,"slug":"cve-2026-91781-gnu-binutils-null-pointer-dereference-in-elf-section-handler","title":"GNU Binutils null pointer dereference in ELF section handler","severity":"low","exploited":false,"published_at":"2026-09-15T09:16:45.153+00:00","url":"https://junglewise.ai/threats/cve-2026-91781-gnu-binutils-null-pointer-dereference-in-elf-section-handler"},{"cve":"CVE-2026-91780","cvss":3.3,"epss":0.0017,"slug":"cve-2026-91780-gnu-binutils-null-pointer-dereference-in-elf-linker","title":"GNU Binutils null pointer dereference in ELF linker","severity":"low","exploited":false,"published_at":"2026-09-15T09:16:44.96+00:00","url":"https://junglewise.ai/threats/cve-2026-91780-gnu-binutils-null-pointer-dereference-in-elf-linker"},{"cve":"CVE-2026-91779","cvss":3.3,"epss":0.0017,"slug":"cve-2026-91779-gnu-binutils-null-pointer-dereference-in-eh-frame-section-offset","title":"GNU Binutils null pointer dereference in eh_frame section offset","severity":"low","exploited":false,"published_at":"2026-09-15T09:16:44.76+00:00","url":"https://junglewise.ai/threats/cve-2026-91779-gnu-binutils-null-pointer-dereference-in-eh-frame-section-offset"},{"cve":"CVE-2026-91752","cvss":7.5,"epss":0.0074,"slug":"cve-2026-91752-gnu-libextractor-stack-based-buffer-overflow-in-ole2-extractor","title":"GNU libextractor stack-based buffer overflow in OLE2 extractor","severity":"high","exploited":false,"published_at":"2026-09-15T01:16:54.967+00:00","url":"https://junglewise.ai/threats/cve-2026-91752-gnu-libextractor-stack-based-buffer-overflow-in-ole2-extractor"},{"cve":"CVE-2026-90831","cvss":5.3,"epss":0.0017,"slug":"cve-2026-90831-gnu-binutils-memory-corruption-in-elf-string-table-handling","title":"GNU Binutils memory corruption in ELF string table handling","severity":"medium","exploited":false,"published_at":"2026-09-14T23:18:59.797+00:00","url":"https://junglewise.ai/threats/cve-2026-90831-gnu-binutils-memory-corruption-in-elf-string-table-handling"},{"cve":"CVE-2026-90830","cvss":5.3,"epss":0.0017,"slug":"cve-2026-90830-gnu-binutils-null-pointer-dereference-in-section-merge","title":"GNU Binutils null pointer dereference in section merge","severity":"medium","exploited":false,"published_at":"2026-09-14T23:18:59.62+00:00","url":"https://junglewise.ai/threats/cve-2026-90830-gnu-binutils-null-pointer-dereference-in-section-merge"},{"cve":"CVE-2026-90829","cvss":5.3,"epss":0.0017,"slug":"cve-2026-90829-gnu-binutils-null-pointer-dereference-in-sht-group-handler","title":"GNU Binutils null pointer dereference in SHT_GROUP handler","severity":"medium","exploited":false,"published_at":"2026-09-14T23:18:59.44+00:00","url":"https://junglewise.ai/threats/cve-2026-90829-gnu-binutils-null-pointer-dereference-in-sht-group-handler"},{"cve":"CVE-2026-90828","cvss":5.3,"epss":0.0019,"slug":"cve-2026-90828-gnu-binutils-null-pointer-dereference-in-elf-orphan-section","title":"GNU Binutils null pointer dereference in ELF orphan section handler","severity":"medium","exploited":false,"published_at":"2026-09-14T22:16:58.69+00:00","url":"https://junglewise.ai/threats/cve-2026-90828-gnu-binutils-null-pointer-dereference-in-elf-orphan-section"},{"cve":"CVE-2026-19542","cvss":5.6,"epss":0.0023,"slug":"cve-2026-19542-gnu-c-library-tdelete-stack-based-buffer-overflow","title":"GNU C Library tdelete stack-based buffer overflow","severity":"medium","exploited":false,"published_at":"2026-09-14T18:17:46.85+00:00","url":"https://junglewise.ai/threats/cve-2026-19542-gnu-c-library-tdelete-stack-based-buffer-overflow"},{"cve":"CVE-2026-19499","cvss":7.7,"epss":0.003,"slug":"cve-2026-19499-gnu-c-library-buffer-overflow-in-strfmon-right-justification","title":"GNU C Library buffer overflow in strfmon right-justification","severity":"high","exploited":false,"published_at":"2026-09-14T18:17:45.753+00:00","url":"https://junglewise.ai/threats/cve-2026-19499-gnu-c-library-buffer-overflow-in-strfmon-right-justification"},{"cve":"CVE-2026-90804","cvss":4.8,"epss":0.002,"slug":"cve-2026-90804-gnu-binutils-heap-buffer-overflow-in-eh-frame-handler","title":"GNU Binutils heap buffer overflow in eh_frame handler","severity":"medium","exploited":false,"published_at":"2026-09-14T17:17:57.163+00:00","url":"https://junglewise.ai/threats/cve-2026-90804-gnu-binutils-heap-buffer-overflow-in-eh-frame-handler"},{"cve":"CVE-2026-90803","cvss":5.3,"epss":0.002,"slug":"cve-2026-90803-gnu-binutils-buffer-overflow-in-elf-x86-64-relocate-section","title":"GNU Binutils buffer overflow in elf_x86_64_relocate_section","severity":"medium","exploited":false,"published_at":"2026-09-14T17:17:56.983+00:00","url":"https://junglewise.ai/threats/cve-2026-90803-gnu-binutils-buffer-overflow-in-elf-x86-64-relocate-section"},{"cve":"CVE-2026-90802","cvss":4.4,"epss":0.0018,"slug":"cve-2026-90802-gnu-binutils-ld-null-pointer-dereference-in-bfd-putl64","title":"GNU Binutils ld null pointer dereference in bfd_putl64","severity":"medium","exploited":false,"published_at":"2026-09-14T17:17:56.8+00:00","url":"https://junglewise.ai/threats/cve-2026-90802-gnu-binutils-ld-null-pointer-dereference-in-bfd-putl64"},{"cve":"CVE-2026-90801","cvss":5.3,"epss":0.0021,"slug":"cve-2026-90801-gnu-binutils-ld-heap-buffer-overflow-in-cache-bwrite","title":"GNU Binutils ld heap buffer overflow in cache_bwrite","severity":"medium","exploited":false,"published_at":"2026-09-14T17:17:56.61+00:00","url":"https://junglewise.ai/threats/cve-2026-90801-gnu-binutils-ld-heap-buffer-overflow-in-cache-bwrite"},{"cve":"CVE-2026-90622","cvss":3.3,"epss":0.0017,"slug":"cve-2026-90622-gnu-libredwg-null-pointer-dereference-in-layer-encoding","title":"GNU libredwg null pointer dereference in LAYER encoding","severity":"low","exploited":false,"published_at":"2026-09-14T04:16:35.913+00:00","url":"https://junglewise.ai/threats/cve-2026-90622-gnu-libredwg-null-pointer-dereference-in-layer-encoding"}],"vendor":{"hub":true,"name":"Gnu","slug":"gnu","homepage":"https://www.gnu.org/","description":"The GNU Project is a collaborative effort to provide a free software operating system and a wide range of software tools.","url":"https://junglewise.ai/threats/vendors/gnu"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":9},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":5},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":4},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":4},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":8},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":19},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":6}],"most_severe":[{"cve":"CVE-2014-6278","cvss":10,"epss":0.914,"slug":"cve-2014-6278-gnu-bash-os-command-injection-via-environment-variables","title":"GNU Bash OS command injection via environment variables","severity":"critical","exploited":true,"published_at":"2025-10-02T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2014-6278-gnu-bash-os-command-injection-via-environment-variables"},{"cve":"CVE-2026-24061","cvss":9.8,"epss":0.9112,"slug":"cve-2026-24061-gnu-inetutils-argument-injection-in-telnetd","title":"GNU InetUtils argument injection in telnetd","severity":"critical","exploited":true,"published_at":"2026-01-26T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2026-24061-gnu-inetutils-argument-injection-in-telnetd"},{"cve":"CVE-2014-6271","cvss":9.8,"slug":"cve-2014-6271-gnu-bourne-again-shell-bash-arbitrary-code-execution-vulnerability","title":"GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability","severity":"critical","exploited":true,"published_at":"2022-01-28T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2014-6271-gnu-bourne-again-shell-bash-arbitrary-code-execution-vulnerability"},{"cve":"CVE-2014-7169","cvss":9.8,"slug":"cve-2014-7169-gnu-bourne-again-shell-bash-arbitrary-code-execution-vulnerability","title":"GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability","severity":"critical","exploited":true,"published_at":"2022-01-28T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2014-7169-gnu-bourne-again-shell-bash-arbitrary-code-execution-vulnerability"},{"cve":"CVE-2023-4911","cvss":7.8,"slug":"cve-2023-4911-gnu-c-library-buffer-overflow-vulnerability","title":"GNU C Library Buffer Overflow Vulnerability","severity":"critical","exploited":true,"published_at":"2023-10-03T18:15:10.463+00:00","url":"https://junglewise.ai/threats/cve-2023-4911-gnu-c-library-buffer-overflow-vulnerability"},{"cve":"CVE-2026-5450","cvss":9.8,"epss":0.0045,"slug":"cve-2026-5450-gnu-glibc-heap-buffer-overflow-in-scanf-mc-specifier","title":"GNU glibc heap buffer overflow in scanf %mc specifier","severity":"critical","exploited":false,"published_at":"2026-04-20T21:16:36.85+00:00","url":"https://junglewise.ai/threats/cve-2026-5450-gnu-glibc-heap-buffer-overflow-in-scanf-mc-specifier"},{"cve":"CVE-2015-8972","cvss":9.8,"slug":"cve-2015-8972-gnu-chess-stack-buffer-overflow-in-validatemove-function","title":"GNU Chess stack buffer overflow in ValidateMove function","severity":"critical","exploited":false,"published_at":"2017-01-23T21:59:00.847+00:00","url":"https://junglewise.ai/threats/cve-2015-8972-gnu-chess-stack-buffer-overflow-in-validatemove-function"},{"cve":"CVE-2023-6246","cvss":8.4,"slug":"cve-2023-6246-gnu-glibc-heap-buffer-overflow-in-vsyslog-internal","title":"GNU glibc heap buffer overflow in __vsyslog_internal","severity":"high","exploited":false,"published_at":"2024-01-31T14:15:48.42+00:00","url":"https://junglewise.ai/threats/cve-2023-6246-gnu-glibc-heap-buffer-overflow-in-vsyslog-internal"},{"cve":"CVE-2016-7543","cvss":8.4,"slug":"cve-2016-7543-gnu-bash-privilege-escalation-via-shellopts-and-ps4-variables","title":"GNU Bash privilege escalation via SHELLOPTS and PS4 variables","severity":"high","exploited":false,"published_at":"2017-01-19T20:59:00.47+00:00","url":"https://junglewise.ai/threats/cve-2016-7543-gnu-bash-privilege-escalation-via-shellopts-and-ps4-variables"},{"cve":"CVE-2023-6779","cvss":8.2,"slug":"cve-2023-6779-gnu-glibc-heap-buffer-overflow-in-vsyslog-internal","title":"GNU glibc heap buffer overflow in __vsyslog_internal","severity":"high","exploited":false,"published_at":"2024-01-31T14:15:48.7+00:00","url":"https://junglewise.ai/threats/cve-2023-6779-gnu-glibc-heap-buffer-overflow-in-vsyslog-internal"}],"generated_at":"2026-09-26T12:07:00.15149+00:00","technologies":[{"name":"Gnu Binutils","slug":"binutils","vulnerabilities":36,"url":"https://junglewise.ai/threats/technologies/binutils"},{"name":"Gnu Glibc","slug":"glibc","vulnerabilities":20,"url":"https://junglewise.ai/threats/technologies/glibc"},{"name":"GnuTLS","slug":"gnutls","vulnerabilities":20,"url":"https://junglewise.ai/threats/technologies/gnutls"},{"name":"Gnu LibreDWG","slug":"libredwg","vulnerabilities":13,"url":"https://junglewise.ai/threats/technologies/libredwg"},{"name":"GNU tar","slug":"tar","vulnerabilities":8,"url":"https://junglewise.ai/threats/technologies/tar"},{"name":"Gnu Bash","slug":"bash","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/bash"},{"name":"GNU C Library","slug":"gnu-c-library","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/gnu-c-library"},{"name":"Gnu Emacs","slug":"emacs","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/emacs"},{"name":"Gnu Wget","slug":"wget","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/wget"},{"name":"Gnu Grub2","slug":"grub2","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/grub2"},{"name":"GNU Coreutils","slug":"coreutils","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/coreutils"},{"name":"Gnu Cpio","slug":"cpio","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/cpio"},{"name":"Gnu Gawk","slug":"gawk","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/gawk"},{"name":"Gnu Fingerd","slug":"fingerd","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/fingerd"}]}