CVE-2026-35343Low· 3.3▾ Sunlitcut: -s (only-delimited) ignored when delimiter is a newline
▾ Sunlit zone — Low / medium · no exploitation signal
impact 18.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 6.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.1%
The cut utility in uutils coreutils incorrectly handles the -s (only-delimited) option when a newline character is specified as the delimiter. The implementation fails to verify the only_delimited flag in the cut_fields_newline_char_delim function, causing the utility to print non-delimited lines that should have been suppressed. This can lead to unexpected data being passed to downstream scripts that rely on strict output filtering.
Zellic finding 3.22. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit 3a07ffc5a9bd4c283e75afa548ba1f1957bad242.
uu_cut < 0.7.0Upgrade to a patched release:
uu_cut 0.7.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-35381Low· 3.3cut: -s ignored in -z -d '' newline-delimiter mode
CVE-2021-1236Medium· 5.3Multiple Cisco products are affected by a vulnerability in the Snort application detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system
CVE-2026-92932Medium· 5.1In the MISP sachertortephp library, the Xml::build() static method in lib/Cake/Utility/Xml.php contains a logic error in the conditional that gates network-based XML fetching
CVE-2026-73468Medium· 6.5A specially crafted packet can cause the premature expiry of multicast forwarding state on affected interfaces, potentially resulting in temporary multicast traffic loss during the affected period.
CVE-2023-41052Medium· 5.3incorrect order of evaluation of side effects for some builtins
CVE-2026-14935Low· 3.7Gstreamer1-plugins-bad-free: gstreamer: webrtcbin accepts remote sdp without a=fingerprint due to inverted presence check