CVE detail
CVE-2026-35020 — CVE-2026-35020
Published 2026-04-06 · Modified 2026-05-29 · Source nvd
UNKNOWN
severity
CVSS-derived band
—
EPSS probability
exploitation probability, 30d
—
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Rejected reason: This CVE ID has been rejected by the its CVE Numbering Authority (CNA). It was determined that the attack requires an attacker to already control arbitrary environment variables, a level of access they consider functionally equivalent to code execution and outside the threat model of CLI tools.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References