Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4355 articles · 196337 vulns · 36/41 feeds (7d)
← Back to list
—
CVE-2026-66486
gnu · cpio

Improper Output Encoding in GNU cpio

Description

GNU cpio is vulnerable to improper encoding or escaping of output in its archive member listing functionality. When listing archive members via cpio -it, member names are printed directly to output without quoting or escaping. An attacker can craft a cpio archive containing member names with embedded newline characters or ANSI escape sequences, causing forged listing entries or terminal control sequence injection when the listing is displayed. This issue has been fixed in commit 2ff9600c9ef32e88759843cdbde74c8db5ae9b30

Affected Products

VendorProductVersions
gnucpio0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
open sourcecpiocert_advisory90%

References

  • https://cert.pl/en/posts/2026/08/CVE-2026-66484(third-party-advisory)
  • https://git.savannah.gnu.org/cgit/cpio.git(product)

Related News (3 articles)

Tier A
Microsoft MSRC12d ago
CVE-2026-66486 Improper Output Encoding in GNU cpio
→ No new info (linked only)
Tier B
BSI Advisories13d ago
[NEU] [niedrig] cpio: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB13d ago
CVE-2026-66486 | GNU Cpio up to 2.15 Archive Member Listing injection
→ No new info (linked only)
CISA KEV❌ No
Actively exploited❌ No
CWECWE-116
PublishedAug 10, 2026
Trending Score8
Source articles3
Independent3
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-41992EXP
Global Buffer Overflow in GNU gzip
Trending: 54
NONECVE-2026-54371
attr < 2.6.0 Symlink Traversal Privilege Escalation via getfattr/setfattr
Trending: 22
NONECVE-2026-77219
GNU Emacs < 31.0.91 Heap Over-Read via PBM/PPM/PGM Image Loader
Trending: 13
NONECVE-2026-66485
Uncontrolled Memory Allocation in GNU cpio
Trending: 8
NONECVE-2026-66484
Path Traversal in GNU cpio
Trending: 8

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 10, 2026
Discovered by ZDM
Aug 10, 2026