Technology · crates.io
coreutils (crates.io) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 44 vulnerabilities in coreutils (crates.io): 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-35372, was published on 22 April 2026.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 0
- Exploited in the wild
- 0
Latest coreutils (crates.io) vulnerabilities
- CVE-2026-35372: uutils coreutils has a UNIX Symbolic Link (Symlink) Following issuelowCVSS 3.1EPSS 0.2%
- Duplicate Advisory: uutils coreutils's User Interface (UI) Misrepresents Critical InformationlowCVSS 3.1
- CVE-2026-35374: uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race ConditionlowCVSS 3.1EPSS 0.1%
- Duplicate Advisory: uutils coreutils has an Incorrect Provision of Specified Functionality Issue in its cut UtilitylowCVSS 3.1
- CVE-2026-35376: uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race ConditionlowCVSS 3.1EPSS 0.1%
- Duplicate Advisory: uutils coreutils has an Improper Handling of Unicode Encoding IssuelowCVSS 3.1
- Duplicate Advisory: uutils coreutils has an Incorrect Authorization issuelowCVSS 3.1
- CVE-2026-35377: uutils coreutils has an Improper Input Validation Issue in its env UtilitylowCVSS 3.1EPSS 0.1%
- CVE-2026-35379: uutils coreutils has an Incorrect Provision of Specified Functionality IssuelowCVSS 3.1EPSS 0.1%
- CVE-2026-35380: uutils coreutils has an Improper Input Validation Issue in its cut UtilitylowCVSS 3.1EPSS 0.2%
- CVE-2026-35375: uutils coreutils has an Improper Handling of Unicode Encoding IssuelowCVSS 3.1EPSS 0.1%
- CVE-2026-35378: uutils coreutils has an Incorrect Short Circuit Evaluation IssuelowCVSS 3.1EPSS 0.2%
- Duplicate Advisory: uutils coreutils has a Time-of-Check to Time-of-Use (TOCTOU) race conditionlowCVSS 3.1
- Duplicate Advisory: uutils coreutils' comm utility incorrectly consumes data from non-regular file inputs before performing comparison operalowCVSS 3.1
- CVE-2026-35360: uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race ConditionlowCVSS 3.1EPSS 0.1%
- CVE-2026-35348: uutils coreutils has an Uncaught Exception When Encountering Valid but Non-UTF-8 PathslowCVSS 3.1EPSS 0.1%
- CVE-2026-35364: uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race ConditionlowCVSS 3.1EPSS 0.1%
- CVE-2026-35357: uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race ConditionlowCVSS 3.1EPSS 0.1%
- CVE-2026-35367: uutils coreutils has an Incorrect Permission Assignment for Critical ResourcelowCVSS 3.1EPSS 0.1%
- Duplicate Advisory: uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race ConditionlowCVSS 3.1
- Duplicate Advisory: uutils coreutils has an Improper Preservation of Permissions issuelowCVSS 3.1
- Duplicate Advisory: uutils coreutils Uses Incorrectly-Resolved Name or ReferencelowCVSS 3.1
- CVE-2026-35359: uutils coreutils has a Link Following issuelowCVSS 3.1EPSS 0.1%
- CVE-2026-35351: uutils coreutils doesn't preserve file ownership during moves across different filesystem boundarieslowCVSS 3.1EPSS 0.1%
- CVE-2026-35350: uutils coreutils doesn't properly handle setuid and setgid bits when ownership preservation failslowCVSS 3.1EPSS 0.1%
Most severe coreutils (crates.io) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-35380: uutils coreutils has an Improper Input Validation Issue in its cut UtilitylowCVSS 3.1EPSS 0.2%
- CVE-2026-35378: uutils coreutils has an Incorrect Short Circuit Evaluation IssuelowCVSS 3.1EPSS 0.2%
- CVE-2026-35372: uutils coreutils has a UNIX Symbolic Link (Symlink) Following issuelowCVSS 3.1EPSS 0.2%
- CVE-2026-35375: uutils coreutils has an Improper Handling of Unicode Encoding IssuelowCVSS 3.1EPSS 0.1%
- CVE-2026-35379: uutils coreutils has an Incorrect Provision of Specified Functionality IssuelowCVSS 3.1EPSS 0.1%
- CVE-2026-35368: uutils coreutils has an Untrusted Search PathlowCVSS 3.1EPSS 0.1%
- CVE-2026-35351: uutils coreutils doesn't preserve file ownership during moves across different filesystem boundarieslowCVSS 3.1EPSS 0.1%
- CVE-2026-35348: uutils coreutils has an Uncaught Exception When Encountering Valid but Non-UTF-8 PathslowCVSS 3.1EPSS 0.1%
- CVE-2026-35377: uutils coreutils has an Improper Input Validation Issue in its env UtilitylowCVSS 3.1EPSS 0.1%
- CVE-2026-35350: uutils coreutils doesn't properly handle setuid and setgid bits when ownership preservation failslowCVSS 3.1EPSS 0.1%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 | |
| 28 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/crates-io-coreutils.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "coreutils (crates.io) vulnerabilities", https://junglewise.ai/threats/technologies/crates-io-coreutils, 28 September 2026.