Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 7

Количество 7

ubuntu логотип

CVE-2026-43895

3 месяца назад

jq is a command-line JSON processor. In 1.8.1 and earlier, jq accepts embedded NUL bytes in import paths at the jq-language level, but later resolves those paths through C string operations during module and data-file lookup. This creates a mismatch between the logical import string that policy or audit code may validate and the on-disk path that jq actually opens.

CVSS3: 4.4
EPSS: Низкий
redhat логотип

CVE-2026-43895

3 месяца назад

jq is a command-line JSON processor. In 1.8.1 and earlier, jq accepts embedded NUL bytes in import paths at the jq-language level, but later resolves those paths through C string operations during module and data-file lookup. This creates a mismatch between the logical import string that policy or audit code may validate and the on-disk path that jq actually opens.

CVSS3: 4.4
EPSS: Низкий
nvd логотип

CVE-2026-43895

3 месяца назад

jq is a command-line JSON processor. In 1.8.1 and earlier, jq accepts embedded NUL bytes in import paths at the jq-language level, but later resolves those paths through C string operations during module and data-file lookup. This creates a mismatch between the logical import string that policy or audit code may validate and the on-disk path that jq actually opens.

CVSS3: 4.4
EPSS: Низкий
msrc логотип

CVE-2026-43895

3 месяца назад

jq: Embedded NUL in jq import paths causes local redaction-policy bypass and preserves sensitive fields in published artifacts

CVSS3: 4.4
EPSS: Низкий
debian логотип

CVE-2026-43895

3 месяца назад

jq is a command-line JSON processor. In 1.8.1 and earlier, jq accepts ...

CVSS3: 4.4
EPSS: Низкий
fstec логотип

BDU:2026-10415

3 месяца назад

Уязвимость файла src/linker.c утилиты для обработки JSON-файлов jq, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 4.4
EPSS: Низкий
redos логотип

ROS-20260708-73-0056

23 дня назад

Уязвимость jq

CVSS3: 4.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-43895

jq is a command-line JSON processor. In 1.8.1 and earlier, jq accepts embedded NUL bytes in import paths at the jq-language level, but later resolves those paths through C string operations during module and data-file lookup. This creates a mismatch between the logical import string that policy or audit code may validate and the on-disk path that jq actually opens.

CVSS3: 4.4
0%
Низкий
3 месяца назад
redhat логотип
CVE-2026-43895

jq is a command-line JSON processor. In 1.8.1 and earlier, jq accepts embedded NUL bytes in import paths at the jq-language level, but later resolves those paths through C string operations during module and data-file lookup. This creates a mismatch between the logical import string that policy or audit code may validate and the on-disk path that jq actually opens.

CVSS3: 4.4
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-43895

jq is a command-line JSON processor. In 1.8.1 and earlier, jq accepts embedded NUL bytes in import paths at the jq-language level, but later resolves those paths through C string operations during module and data-file lookup. This creates a mismatch between the logical import string that policy or audit code may validate and the on-disk path that jq actually opens.

CVSS3: 4.4
0%
Низкий
3 месяца назад
msrc логотип
CVE-2026-43895

jq: Embedded NUL in jq import paths causes local redaction-policy bypass and preserves sensitive fields in published artifacts

CVSS3: 4.4
0%
Низкий
3 месяца назад
debian логотип
CVE-2026-43895

jq is a command-line JSON processor. In 1.8.1 and earlier, jq accepts ...

CVSS3: 4.4
0%
Низкий
3 месяца назад
fstec логотип
BDU:2026-10415

Уязвимость файла src/linker.c утилиты для обработки JSON-файлов jq, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 4.4
0%
Низкий
3 месяца назад
redos логотип
ROS-20260708-73-0056

Уязвимость jq

CVSS3: 4.4
0%
Низкий
23 дня назад

Уязвимостей на страницу