CVE-2026-0708

A flaw was found in libucl. A remote attacker could exploit this by providing a specially crafted Universal Configuration Language (UCL) input that contains a key with an embedded null byte. This can cause a segmentation fault (SEGV fault) in the `ucl_object_emit` function when parsing and emitting the object, leading to a Denial of Service (DoS) for the affected system.
References
Link Resource
https://access.redhat.com/security/cve/CVE-2026-0708 Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2427770 Issue Tracking Third Party Advisory
https://github.com/vstakhov/libucl/issues/323 Exploit Issue Tracking Vendor Advisory
https://github.com/vstakhov/libucl/issues/323 Exploit Issue Tracking Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:vstakhov:libucl:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:11

Type Values Removed Values Added
References () https://bugzilla.redhat.com/show_bug.cgi?id=2427770 - Third Party Advisory, Issue Tracking () https://bugzilla.redhat.com/show_bug.cgi?id=2427770 - Issue Tracking, Third Party Advisory
References () https://github.com/vstakhov/libucl/issues/323 - Issue Tracking, Vendor Advisory, Exploit () https://github.com/vstakhov/libucl/issues/323 - Exploit, Issue Tracking, Vendor Advisory

11 May 2026, 17:14

Type Values Removed Values Added
CPE cpe:2.3:a:vstakhov:libucl:*:*:*:*:*:*:*:*
First Time Vstakhov
Vstakhov libucl
References () https://access.redhat.com/security/cve/CVE-2026-0708 - () https://access.redhat.com/security/cve/CVE-2026-0708 - Third Party Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2427770 - () https://bugzilla.redhat.com/show_bug.cgi?id=2427770 - Third Party Advisory, Issue Tracking
References () https://github.com/vstakhov/libucl/issues/323 - () https://github.com/vstakhov/libucl/issues/323 - Issue Tracking, Vendor Advisory, Exploit
Summary
  • (es) Se encontró un fallo en libucl. Un atacante remoto podría explotar esto al proporcionar una entrada de Universal Configuration Language (UCL) especialmente diseñada que contiene una clave con un byte nulo incrustado. Esto puede causar un fallo de segmentación (fallo SEGV) en la función 'ucl_object_emit' al analizar y emitir el objeto, lo que lleva a una denegación de servicio (DoS) para el sistema afectado.

17 Mar 2026, 14:20

Type Values Removed Values Added
References () https://github.com/vstakhov/libucl/issues/323 - () https://github.com/vstakhov/libucl/issues/323 -

17 Mar 2026, 04:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-17 04:16

Updated : 2026-06-17 10:11


NVD link : CVE-2026-0708

Mitre link : CVE-2026-0708

CVE.ORG link : CVE-2026-0708


JSON object : View

Products Affected

vstakhov

  • libucl
CWE
CWE-125

Out-of-bounds Read