


Perceptive Security
SOC/SIEM Consultancy

A flaw was found in libucl. A remote attacker could exploit this by providing a specially crafted Universal Configuration Language (UCL) input that contains a k…
Published:
16 March 2026 at 23:00:00
Alert date:
17 March 2026 at 05:01:05
Source:
nvd.nist.gov
Supply Chain & Dependencies
A vulnerability in libucl allows remote attackers to cause denial of service through specially crafted Universal Configuration Language (UCL) input containing keys with embedded null bytes. The flaw triggers a segmentation fault in the ucl_object_emit function during parsing and emitting operations. This results in application crashes and system unavailability. The vulnerability affects the Universal Configuration Language parsing library. Remote exploitation is possible without authentication requirements.
Technical details
Mitigation steps:
Affected products:
libucl
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-0708
https://access.redhat.com/security/cve/CVE-2026-0708
https://bugzilla.redhat.com/show_bug.cgi?id=2427770
https://github.com/vstakhov/libucl/issues/323
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
