PT-2026-34479 · Unknown · Uutils Coreutils

·

CVE-2026-35343

·

Published

2026-04-22

·

Updated

2026-07-06

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions uutils coreutils (affected versions not specified)
Description The cut utility incorrectly handles the -s (only-delimited) option when a newline character is used as the delimiter. The cut fields newline char delim() function fails to verify the only delimited flag, which results in the utility printing non-delimited lines that should have been suppressed. This behavior may cause unexpected data to be passed to downstream scripts that depend on strict output filtering.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-35343
GHSA-HJ9R-8PFM-RMJJ
GHSA-WV33-5PXH-R7J7

Affected Products

Uutils Coreutils