CVE-2026-35343: cut: -s (only-delimited) ignored when delimiter is a newline
The cut utility in uutils coreutils incorrectly handles the -s (only-delimited) option when a newline character is specified as the delimiter. The implementation fails to verify the only_delimited flag in the cut_fields_newline_char_delim function, causing the utility to print non-delimited lines that should have been suppressed. This can lead to unexpected data being passed to downstream scripts that rely on strict output filtering.
Zellic finding 3.22. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit 3a07ffc5a9bd4c283e75afa548ba1f1957bad242.
References
- github.com/advisories/GHSA-wv33-5pxh-r7j7
- github.com/uutils/coreutils/commit/9bbb58b746c41802278b0cba738eebbf21517cf7
- github.com/uutils/coreutils/pull/11143
- github.com/uutils/coreutils/releases/tag/0.7.0
- github.com/uutils/coreutils/security/advisories/GHSA-wv33-5pxh-r7j7
- nvd.nist.gov/vuln/detail/CVE-2026-35343
Code Behaviors & Features
Detect and mitigate CVE-2026-35343 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →