CVE-2026-35373Uutils · Coreutils
Vulnerability data via NVD (ingested)
A logic error in the ln utility of uutils coreutils causes the program to reject source paths containing non-UTF-8 filename bytes when using target-directory forms (e.g., ln SOURCE... DIRECTORY). While GNU ln treats filenames as raw bytes and creates the links correctly, the uutils implementation enforces UTF-8 encoding, resulting in a failure to stat the file and a non-zero exit code. In environments where automated scripts or system tasks process valid but non-UTF-8 filenames common on Unix filesystems, this divergence causes the utility to fail, leading to a local denial of service for those specific operations.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-35373product:"Uutils Coreutils"http.html:"Coreutils"More intel sources (5)
vuln:CVE-2026-35373vulnerabilities.cve_id: CVE-2026-35373CVE-2026-35373CVE-2026-35373"CVE-2026-35373" exploit -site:nvd.nist.gov