Description
A logic error in the cut utility of uutils coreutils causes the program to incorrectly interpret the literal two-byte string '' (two single quotes) as an empty delimiter. The implementation mistakenly maps this string to the NUL character for both the -d (delimiter) and --output-delimiter options. This vulnerability can lead to silent data corruption or logic errors in automated scripts and data pipelines that process strings containing these characters, as the utility may unintentionally split or join data on NUL bytes rather than the intended literal characters.
Published: 2026-04-22
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The cut utility in uutils coreutils contains a logic flaw—an instance of CWE‑20 (improper input validation) and is also catalogued under NVD‑CWE‑noinfo—where the literal two‑byte string '' is misinterpreted as an empty delimiter, effectively mapping it to a NUL character for both the -d and --output-delimiter options. This misparsing can cause automated scripts and data pipelines that rely on precise delimiter behavior to silently corrupt data or produce incorrect output, leading to logic errors and potential data loss. Although it does not grant code execution, it undermines data integrity.

Affected Systems

The vulnerability exists in the uutils coreutils cut command, affecting all installations that have not been updated to version 0.8.0 or later. The patch is included in the 0.8.0 release, so systems running earlier versions of uutils coreutils are at risk.

Risk and Exploitability

The CVSS base score of 5.5 indicates moderate severity. Classified as CWE‑20 (improper input validation) and listed under NVD‑CWE‑noinfo, an attacker would need to influence the input passed to cut, typically by running or modifying a script that uses the tool. The exploit does not require special privileges and can be triggered locally, but it does not lead to remote code execution. The EPSS score is <1% (0.0002), and the vulnerability is not listed in the CISA KEV, indicating it is not known to be widely exploited in the wild yet.

Generated by OpenCVE AI on April 30, 2026 at 04:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade uutils coreutils to version 0.8.0 or later where the logic error is corrected.
  • Audit any automated scripts or data pipelines that use cut with the literal "" delimiter to ensure they no longer rely on this misparsing behavior.
  • Modify or replace problematic cut calls with safer delimiters or an alternative method to prevent silent data corruption.

Generated by OpenCVE AI on April 30, 2026 at 04:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-m2pg-c7m6-77pj uutils coreutils has an Improper Input Validation Issue in its cut Utility
History

Wed, 29 Apr 2026 16:00:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:uutils:coreutils:*:*:*:*:*:rust:*:*

Mon, 27 Apr 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Uutils
Uutils coreutils
Vendors & Products Uutils
Uutils coreutils

Wed, 22 Apr 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 22 Apr 2026 16:30:00 +0000

Type Values Removed Values Added
Description A logic error in the cut utility of uutils coreutils causes the program to incorrectly interpret the literal two-byte string '' (two single quotes) as an empty delimiter. The implementation mistakenly maps this string to the NUL character for both the -d (delimiter) and --output-delimiter options. This vulnerability can lead to silent data corruption or logic errors in automated scripts and data pipelines that process strings containing these characters, as the utility may unintentionally split or join data on NUL bytes rather than the intended literal characters.
Title uutils coreutils cut Local Logic Error and Data Integrity Issue in Delimiter Parsing
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Uutils Coreutils
cve-icon MITRE

Status: PUBLISHED

Assigner: canonical

Published:

Updated: 2026-04-22T16:57:53.616Z

Reserved: 2026-04-02T12:58:56.089Z

Link: CVE-2026-35380

cve-icon Vulnrichment

Updated: 2026-04-22T16:57:48.221Z

cve-icon NVD

Status : Analyzed

Published: 2026-04-22T17:16:43.047

Modified: 2026-04-29T15:57:19.427

Link: CVE-2026-35380

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T04:15:26Z

Weaknesses