Logo
vulnerabilityCVE-2026-43895
Name
CVE-2026-43895
Source
NVD ( link)Debian ( link)
Description
jq is a command-line JSON processor. In 1.8.1 and earlier, jq accepts embedded NUL bytes in import paths at the jq-language level, but later resolves those paths through C string operations during module and data-file lookup. This creates a mismatch between the logical import string that policy or audit code may validate and the on-disk path that jq actually opens.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
jq
Exploitable

Vulnerability Ratings#


4.4
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
1.7.1
Exploitable
openwrt
master
1.8.1-r2
Exploitable
openwrt
openwrt-25.12
1.8.1-r2
Exploitable
yocto
kirkstone
1.6+gitX
Exploitable
yocto
master
1.8.1
Exploitable
yocto
scarthgap
1.7.1
Exploitable