buildroot ▾
›
2025.02.x ▾
›
vulnerability
›
CVE-2026-44777
Component Overview
Vulnerability Overview
Name
CVE-2026-44777
Source
NVD (
link
)
Debian (
link
)
Description
jq is a command-line JSON processor. In 1.8.2rc1 and earlier, the ordinary module loader recurses without cycle detection when two otherwise valid modules include each other.
CWEs
CWE-674
Published Date
May 11, 2026
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://github.com/jqlang/jq/security/advisories/GHSA-rmpv-jgvr-wpr9
Exploit
https://github.com/jqlang/jq/security/advisories/GHSA-rmpv-jgvr-wpr9
Exploit
Analysis
#
Affected Component
Analysis
jq
Exploitable
Vulnerability Ratings
#
5.4
CVSSv4
5.5
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
jq
buildroot
master
1.8.1
Exploitable
jq
openwrt
master
1.8.1-r2
Exploitable
jq
openwrt
openwrt-25.12
1.8.1-r2
Exploitable
jq
yocto
kirkstone
1.6+gitX
Exploitable
jq
yocto
master
1.8.1
Exploitable
jq
yocto
scarthgap
1.7.1
Exploitable