GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability

GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute code.

Published 31 Aug 2026Updated 31 Aug 202670 sources
CVSS 10.0 ✓ VERIFIED REFERENCE△ CISA KEV

What happened

GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute code.

Affected versions

Bourne-Again Shell (Bash): See original advisory Fixed: See vendor advisory.

Why it matters

This source correlation may provide earlier visibility while structured CVE metadata is still being updated.

Detection & mitigation

  • Review the original advisory and validate affected versions.
  • Apply vendor-provided updates or mitigations when available.

Public PoC references

RepositoryAuthorFirst seenReference
Exploit-DB 38849Advantech Switch - 'Shellshock' Bash Environment Variable Command Injection (Metasploit)Metasploit2015-12-02VerifiedExploit-DB 34777GNU Bash - Environment Variable Command Injection (Metasploit)Shaun Colley2014-09-25VerifiedExploit-DB 39918IPFire - 'Shellshock' Bash Environment Variable Command Injection (Metasploit)Metasploit2016-06-10VerifiedExploit-DB 34895Bash CGI - 'Shellshock' Remote Command Injection (Metasploit)Fady Mohammed Osman2014-10-06VerifiedExploit-DB 34839IPFire - CGI Web Interface (Authenticated) Bash Environment Variable Code InjectionClaudio Viviani2014-10-01VerifiedExploit-DB 36503QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)Patrick Pellegrino2015-03-26VerifiedExploit-DB 36504QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)Patrick Pellegrino2015-03-26VerifiedExploit-DB 40619TrendMicro InterScan Web Security Virtual Appliance - 'Shellshock' Remote Command InjectionHacker Fantastic2016-10-21VerifiedExploit-DB 40938RedStar 3.0 Server - 'Shellshock' 'BEAM' / 'RSSMON' Command InjectionHacker Fantastic2016-12-18VerifiedExploit-DB 34900Apache mod_cgi - 'Shellshock' Remote Command InjectionFederico Galatolo2014-10-06VerifiedExploit-DB 34766Bash - 'Shellshock' Environment Variables Command InjectionPrakhar Prasad & Subho Halder2014-09-25VerifiedExploit-DB 35115CUPS Filter - Bash Environment Variable Code Injection (Metasploit)Metasploit2014-10-29VerifiedExploit-DB 34765GNU Bash - 'Shellshock' Environment Variable Command InjectionStephane Chazelas2014-09-25VerifiedExploit-DB 34860GNU bash 4.3.11 - Environment Variable dhclient@0x00string2014-10-02VerifiedExploit-DB 34879OpenVPN 2.2.29 - 'Shellshock' Remote Command Injectionhobbily plunt2014-10-04VerifiedExploit-DB 34896Postfix SMTP 4.2.x < 4.2.48 - 'Shellshock' Remote Command InjectionPhil Blank2014-10-06VerifiedExploit-DB 34862Pure-FTPd - External Authentication Bash Environment Variable Code Injection (Metasploit)Metasploit2014-10-02VerifiedExploit-DB 42938Qmail SMTP - Bash Environment Variable Injection (Metasploit)Metasploit2017-10-02VerifiedExploit-DB 37816Cisco Unified Communications Manager - Multiple VulnerabilitiesBernhard Mueller2015-08-18VerifiedExploit-DB 36609Kemp Load Master 7.1.16 - Multiple VulnerabilitiesRoberto Suggi Liverani2015-04-02VerifiedExploit-DB 35146PHP < 5.6.2 - 'Shellshock' Safe Mode / disable_functions Bypass / Command InjectionRyan King (Starfall)2014-11-03VerifiedSploitusNetworkAlarm CLI tool monitors local network traffic for nmap, Nikto, Shellshock, and cleartext credential attacks.KitPloit2026-08-31T07:37:25Candidatekitploit.comNetworkAlarm CLI tool monitors local network traffic for nmap, Nikto, Shellshock, and cleartext credential attacks.ru2026-08-31T07:37:25Candidate