Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-44777

Опубликовано: 11 мая 2026
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

jq is a command-line JSON processor. In 1.8.2rc1 and earlier, the ordinary module loader recurses without cycle detection when two otherwise valid modules include each other.

A flaw was found in jq, a command line JSON processor. The module loader fails to perform cycle detection when resolving imports. This missing cycle detection allows an attacker who can supply crafted modules with circular dependencies to exhaust the stack memory, causing an application crash, resulting in a denial of service.

Отчет

To exploit this vulnerability, an attacker needs to supply crafted modules with circular dependencies to be processed by the jq module loader. This allows the attacker to cause an application crash with no other security impact. Due to these reasons, this issue has been rated with a moderate severity.

Меры по смягчению последствий

Do not process untrusted input with the jq command line JSON processor.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/controller-rhel9Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/hub-rhel9Fix deferred
Red Hat Ansible Automation Platform 2automation-controllerFix deferred
Red Hat Ceph Storage 4jqFix deferred
Red Hat Enterprise Linux 10jqOut of support scope
Red Hat Enterprise Linux 8jqFix deferred
Red Hat Enterprise Linux 9jqOut of support scope
Red Hat OpenShift Container Platform 4rhcosFix deferred
Red Hat Hardened Imagesjq-main-1.8.2-0.1.hum1FixedRHSA-2026:2998625.06.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-674
https://bugzilla.redhat.com/show_bug.cgi?id=2469192jq: stack overflow in module loading on mutual include

EPSS

Процентиль: 6%
0.00161
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
3 месяца назад

jq is a command-line JSON processor. In 1.8.2rc1 and earlier, the ordinary module loader recurses without cycle detection when two otherwise valid modules include each other.

CVSS3: 5.5
nvd
3 месяца назад

jq is a command-line JSON processor. In 1.8.2rc1 and earlier, the ordinary module loader recurses without cycle detection when two otherwise valid modules include each other.

msrc
3 месяца назад

jq: stack overflow in module loading on mutual `include`

CVSS3: 5.5
debian
3 месяца назад

jq is a command-line JSON processor. In 1.8.2rc1 and earlier, the ordi ...

CVSS3: 6.2
redos
23 дня назад

Уязвимость jq

EPSS

Процентиль: 6%
0.00161
Низкий

5.5 Medium

CVSS3