PT-2026-25869 · Libucl · Libucl

Published

2026-03-17

·

Updated

2026-03-17

·

CVE-2026-0708

CVSS v3.1
8.3
VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:H
A flaw was found in libucl. A remote attacker could exploit this by providing a specially crafted Universal Configuration Language (UCL) input that contains a key with an embedded null byte. This can cause a segmentation fault (SEGV fault) in the
ucl object emit
function when parsing and emitting the object, leading to a Denial of Service (DoS) for the affected system.

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

CVE-2026-0708

Affected Products

Libucl