CVE-2026-35346Low· 3.3▾ Sunlitcomm: lossy UTF-8 conversion silently corrupts non-UTF-8 output
▾ Sunlit zone — Low / medium · no exploitation signal
impact 18.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 6.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.2%
0.2% → 0.2%
The comm utility in uutils coreutils silently corrupts data by performing lossy UTF-8 conversion on all output lines. The implementation uses String::from_utf8_lossy(), which replaces invalid UTF-8 byte sequences with the Unicode replacement character (U+FFFD). This behavior differs from GNU comm, which processes raw bytes and preserves the original input. This results in corrupted output when the utility is used to compare binary files or files using non-UTF-8 legacy encodings.
Zellic finding 3.34. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit 3a07ffc5a9bd4c283e75afa548ba1f1957bad242.
uu_comm < 0.6.0Upgrade to a patched release:
uu_comm 0.6.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-35347Medium· 4.4comm: FIFO/pipe inputs are drained before comparison (data loss / hang)
CVE-2026-35366Medium· 4.4printenv: environment variables with invalid UTF-8 are silently skipped (evades inspection)
CVE-2023-29541High· 8.8Firefox did not properly handle downloads of files ending in <code>.desktop</code>, which can be interpreted to run attacker-controlled commands
CVE-2022-24682Medium· 6.1An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starting in December 2021
CVE-2026-25940High· 8.1jsPDF is a library to generate PDFs in JavaScript
GHSA-cwv4-h3j5-w3cfLow· 3.7rama has Stored XSS in ServeDir HTML directory listing via unescaped file names and URI path