Report: CVE-2026-0708 - Libucl: libucl: denial of service via embedded null byte in ucl input

Report: CVE-2026-0708 - Libucl: libucl: denial of service via embedded null byte in ucl input

CVE ID :CVE-2026-0708 Published : March 17, 2026, 2:28 a.m. | 1 hour, 48 minutes ago Description :A flaw was found in libucl. A remote attacker could exploit this by providing a specially crafted Universal Configuration Language (UCL) input that contains a key with an embedded null byte. This can cause a segmentation fault (SEGV fault) in the `ucl_object_emit` function when parsing and emitting the object, leading to a Denial of Service (DoS) for the affected system. Severity: 8.3 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
HIGH
Published
March 17, 2026
Impact: Denial of Service