Disclosure summary
`cut` routes `-z -d ''` through a special newline-delimiter path that ignores the `-s` only-delimited flag, emitting whole undelimited records (plus NUL) that should be suppressed. Pipelines relying on `cut -s` to drop undelimited records process data that should be filtered. ``` printf 'abc' | cut -z -d '' -s -f 1 | od -An -tx1 # GNU: no output ; uutils: 61 62 63 00 ``` --- _Zellic private finding (zellic-ext/coreutils-private PR #102). Reported in the Zellic *uutils coreutils Program Security Assessment* (for Canonical, Jan 2026), audited commit `3a07ffc5a9bd4c283e75afa548ba1f1957bad242`._
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-pmfc-4wjj-gmhx
Open original source · Updated Oct 06, 2026
cut: -s ignored in -z -d '' newline-delimiter mode
Source severity: LOW / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| rust | uu_cut | < 0.8.0 | 0.8.0 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-07-06T17:54:29-04:00
MODIFIED 2026-10-06T14:15:54-04:00
INGESTED 2026-10-08T12:05:11-04:00