CVE Tools

Patch

18 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Patch, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Patch CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Patch CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-022
2026-030
2026-040
2026-050
2026-060
2026-073
2026-080
2026-090

Severity

How the 18 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • High739%
  • Medium1161%

Latest CVEs

The 15 most recently published vulnerabilities affecting Patch.

  1. CVE-2026-11391Tanium addressed a SQL injection vulnerability in Patch.6.3
  2. CVE-2026-56289Loop with Unreachable Exit Condition in GNU patch5.5
  3. CVE-2026-56288NULL Pointer Dereference in GNU patch5.5
  4. CVE-2025-15326Tanium addressed an improper access controls vulnerability in Patch.4.3
  5. CVE-2025-15337Tanium addressed an incorrect default permissions vulnerability in Patch.6.5
  6. CVE-2021-45261An Invalid Pointer vulnerability exists in GNU patch 2.7 via the another_hunk function, which causes a Denial of Service.5.5
  7. CVE-2019-20633GNU patch through 2.7.6 contains a free(p_line[p_end]) Double Free vulnerability in the function another_hunk in pch.c that can cause a denial of service via a crafted patch file. NOTE: this issue ...5.5
  8. CVE-2015-1396A Directory Traversal vulnerability exists in the GNU patch before 2.7.4. A remote attacker can write to arbitrary files via a symlink attack in a patch file. NOTE: this issue exists because of an ...7.5
  9. CVE-2018-20969do_ed_script in pch.c in GNU patch through 2.7.6 does not block strings beginning with a ! character. NOTE: this is the same commit as for CVE-2019-13638, but the ! syntax is specific to ed, and is...7.8
  10. CVE-2019-13638GNU patch through 2.7.6 is vulnerable to OS shell command injection that can be exploited by opening a crafted patch file that contains an ed style diff payload with shell metacharacters. The ed ed...7.8
  11. CVE-2019-13636In GNU patch through 2.7.6, the following of symlinks is mishandled in certain cases other than input files. This affects inp.c and util.c.5.9
  12. CVE-2018-1000156GNU Patch version 2.7.6 contains an input validation vulnerability when processing patch files, specifically the EDITOR_PROGRAM invocation (using ed) can result in code execution. This attack appea...7.8
  13. CVE-2018-6951An issue was discovered in GNU patch through 2.7.6. There is a segmentation fault, associated with a NULL pointer dereference, leading to a denial of service in the intuit_diff_type function in pch...7.5
  14. CVE-2018-6952A double free exists in the another_hunk function in pch.c in GNU patch through 2.7.6.7.5
  15. CVE-2016-10713An issue was discovered in GNU patch before 2.7.6. Out-of-bounds access within pch_write_line() in pch.c can possibly lead to DoS via a crafted input file.5.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store