CVE-2026-35365: CWE-59: Improper Link Resolution Before File Access ('Link Following') in Uutils coreutils
The mv utility in uutils coreutils improperly handles symbolic links when moving directory trees across filesystem boundaries by expanding symlinks instead of preserving them. This behavior can cause resource exhaustion, unexpected duplication of sensitive data, or infinite recursion due to symlink loops. The vulnerability is tracked as CVE-2026-35365 with a medium severity rating and a CVSS score of 6.6. No patch or official remediation has been confirmed yet.
AI Analysis
Technical Summary
CVE-2026-35365 describes a vulnerability in the mv utility of uutils coreutils where symbolic links within directory trees are expanded rather than preserved during moves across filesystem boundaries. This improper link resolution (CWE-59) can lead to resource exhaustion through excessive disk usage or time consumption, unintended copying of sensitive data, and potential infinite recursion caused by symlink loops. The vulnerability affects version 0 of the product, with no known exploits in the wild and no confirmed remediation level or patch available at this time.
Potential Impact
The vulnerability can cause resource exhaustion by copying large external directories referenced by symlinks, potentially filling disk space or consuming excessive time. It may also lead to unintended duplication of sensitive data into locations where it should not reside, increasing the risk of data exposure. Additionally, symlink loops can cause infinite recursion and repeated copying, further exacerbating resource consumption and operational disruption.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should exercise caution when using the mv utility on directory trees containing symbolic links across filesystem boundaries, especially with untrusted or sensitive data. Avoid moving directories with complex symlink structures or consider alternative tools that correctly preserve symlinks.
CVE-2026-35365: CWE-59: Improper Link Resolution Before File Access ('Link Following') in Uutils coreutils
Description
The mv utility in uutils coreutils improperly handles symbolic links when moving directory trees across filesystem boundaries by expanding symlinks instead of preserving them. This behavior can cause resource exhaustion, unexpected duplication of sensitive data, or infinite recursion due to symlink loops. The vulnerability is tracked as CVE-2026-35365 with a medium severity rating and a CVSS score of 6.6. No patch or official remediation has been confirmed yet.
CVSS v3.1
Score 6.6medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-35365 describes a vulnerability in the mv utility of uutils coreutils where symbolic links within directory trees are expanded rather than preserved during moves across filesystem boundaries. This improper link resolution (CWE-59) can lead to resource exhaustion through excessive disk usage or time consumption, unintended copying of sensitive data, and potential infinite recursion caused by symlink loops. The vulnerability affects version 0 of the product, with no known exploits in the wild and no confirmed remediation level or patch available at this time.
Potential Impact
The vulnerability can cause resource exhaustion by copying large external directories referenced by symlinks, potentially filling disk space or consuming excessive time. It may also lead to unintended duplication of sensitive data into locations where it should not reside, increasing the risk of data exposure. Additionally, symlink loops can cause infinite recursion and repeated copying, further exacerbating resource consumption and operational disruption.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should exercise caution when using the mv utility on directory trees containing symbolic links across filesystem boundaries, especially with untrusted or sensitive data. Avoid moving directories with complex symlink structures or consider alternative tools that correctly preserve symlinks.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- canonical
- Date Reserved
- 2026-04-02T12:58:56.088Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 69e8f7d319fe3cd2cdd00d07
Added to database: 04/22/2026, 16:31:15 UTC
Last enriched: 07/06/2026, 23:15:22 UTC
Last updated: 07/31/2026, 19:22:58 UTC
Views: 114
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.