OVERVIEW CVE-2026-35366 affects the printenv utility in uutils coreutils, a Rust-based implementation of core Unix utilities. The vulnerability stems from improper handling of environment variables containing invalid UTF-8 byte sequences. Rather than displaying raw bytes as POSIX standards permit, the utility silently omits these entries, creating a visibility gap that obscures potentially malicious environment variables from administrator inspection and security auditing tools. SEVERITY This vulnerability carries a CVSS v3.1 score of 4.4 (MEDIUM) with a local attack vector requiring low privilege access and no user interaction. The impact is limited to low-level confidentiality and integrity concerns, with no availability impact. While the EPSS score of 0.00011 indicates extremely low prevalence in the wild relative to other CVEs, the practical risk lies in its ability to facilitate environment-based attacks such as LD_PRELOAD library injection that could evade detection, making it more relevant to defense evasion scenarios than to direct system compromise. EXPLOITATION STATUS There is no evidence of active exploitation, and the vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog. No public exploit code appears to be available. Community attention remains minimal, as reflected by the low FAUCET risk score of 30/100 and inactive status on security hotlists. Organizations should prioritize patching only if they deploy uutils coreutils in security-sensitive environments where environment variable auditing is a critical control.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 0.6.0CPE match | cpe:2.3:a:uutils:coreutils:*:*:*:*:*:rust:*:* | ||
< 0.6.0CPE matchmatch criteria | cpe:2.3:a:uutils:coreutils:*:*:*:*:*:rust:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.