{"id":"CVE-2026-35343","aliases":["GHSA-wv33-5pxh-r7j7"],"url":"https://o3.security/vulnerability/CVE-2026-35343","summary":"uutils coreutils cut Inconsistent Output Suppression with Newline Delimiters","details":"The cut utility in uutils coreutils incorrectly handles the -s (only-delimited) option when a newline character is specified as the delimiter. The implementation fails to verify the only_delimited flag in the cut_fields_newline_char_delim function, causing the utility to print non-delimited lines that should have been suppressed. This can lead to unexpected data being passed to downstream scripts that rely on strict output filtering.","published":"2026-04-22T16:07:44.261Z","modified":"2026-08-05T03:32:04.540543071Z","cvss":{"score":3.3,"severity":"LOW","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"uu_cut","fixedVersion":"0.7.0"}],"fix":{"url":"https://github.com/uutils/coreutils/pull/11143","label":"uutils/coreutils#11143"},"references":[{"type":"WEB","url":"https://github.com/uutils"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/35xxx/CVE-2026-35343.json"},{"type":"ADVISORY","url":"https://github.com/uutils/coreutils/releases/tag/0.7.0"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-35343"},{"type":"FIX","url":"https://github.com/uutils/coreutils/pull/11143"},{"type":"PACKAGE","url":"https://github.com/uutils/coreutils"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-05T03:32:04.540543071Z"}}