{"id":"CVE-2026-35381","aliases":["GHSA-pmfc-4wjj-gmhx"],"title":"cut: -s ignored in -z -d '' newline-delimiter mode","summary":"cut: -s ignored in -z -d '' newline-delimiter mode","severity":"low","cvss":3.3,"cwe":["CWE-684"],"vendor":"uu_cut","product":"uu_cut","ecosystem":"rust","affected":["uu_cut < 0.7.0"],"patched":["uu_cut 0.7.0"],"published":"2026-07-06","updated":"2026-07-06","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-pmfc-4wjj-gmhx","references":[{"url":"https://github.com/uutils/coreutils/security/advisories/GHSA-pmfc-4wjj-gmhx"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-35381"},{"url":"https://github.com/uutils/coreutils/pull/11394"},{"url":"https://github.com/uutils/coreutils/commit/483f13e91830c468262aa1e010e753d6ae99c898"},{"url":"https://github.com/uutils/coreutils/releases/tag/0.8.0"},{"url":"https://github.com/advisories/GHSA-pmfc-4wjj-gmhx"}],"tags":["ghsa","rust"],"epss":0.00182,"epssPercentile":0.08037,"ingestedAt":"2026-07-06T22:47:14.051Z","slug":"CVE-2026-35381","body":"## Overview\n\n`cut` routes `-z -d ''` through a special newline-delimiter path that ignores the `-s` only-delimited flag, emitting whole undelimited records (plus NUL) that should be suppressed. Pipelines relying on `cut -s` to drop undelimited records process data that should be filtered.\n```\nprintf 'abc' | cut -z -d '' -s -f 1 | od -An -tx1   # GNU: no output ; uutils: 61 62 63 00\n```\n\n---\n_Zellic private finding (zellic-ext/coreutils-private PR #102). Reported in the Zellic *uutils coreutils Program Security Assessment* (for Canonical, Jan 2026), audited commit `3a07ffc5a9bd4c283e75afa548ba1f1957bad242`._\n\n## Affected packages\n\n- `uu_cut < 0.7.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `uu_cut 0.7.0`","depth":"sunlit","depthScore":18,"depthScoreParts":{"impact":18.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}