CVE-2026-0708
EUVD-2026-1253417.03.2026, 04:16
A flaw was found in libucl. A remote attacker could exploit this by providing a specially crafted Universal Configuration Language (UCL) input that contains a key with an embedded null byte. This can cause a segmentation fault (SEGV fault) in the `ucl_object_emit` function when parsing and emitting the object, leading to a Denial of Service (DoS) for the affected system.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| vstakhov | libucl | 𝑥 ≤ 0.9.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration