VulnSea

The GNU C Library has 5 CVEs on record. 5 were published in the last 90 days. The busiest recent month was September 2026 with 5. The median CVSS is 5.9 (medium). None have a confirmed exploitation report.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
5.9
Publish → KEV
Last 90 days
5 prev 0

Products

  • glibc 5
5
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

The GNU C Library vulnerabilities

CVEs affecting The GNU C Library, newest first. Open any entry for full detail, references, and exploit status.

5 CVEsRSS

CVE-2026-8674Medium· 5.3
4d ago

Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assert…

Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assert…

SunlitThe GNU C Library · glibcEPSS 0.31%via NVD
CVE-2026-80489Medium· 5.9
6d ago

Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to h…

Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to h…

SunlitThe GNU C Library · glibcEPSS 0.41%via NVD
CVE-2026-77117Medium· 5.9
6d ago

Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to…

Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to…

SunlitThe GNU C Library · glibcEPSS 0.41%via NVD
CVE-2026-19542Medium· 5.6
1w ago

Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application. The tdelete implementation keeps an expl…

Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application. The tdelete implementation keeps an expl…

SunlitThe GNU C Library · glibcEPSS 0.28%via NVD
CVE-2026-19499High· 7.7
1w ago

Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding. Exploitation requires an application code path tha…

Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding. Exploitation requires an application code path tha…

TwilightThe GNU C Library · glibcEPSS 0.38%via NVD
The GNU C Library vulnerabilities (CVEs) · VulnSea