Количество 7
Количество 7
CVE-2026-43895
jq is a command-line JSON processor. In 1.8.1 and earlier, jq accepts embedded NUL bytes in import paths at the jq-language level, but later resolves those paths through C string operations during module and data-file lookup. This creates a mismatch between the logical import string that policy or audit code may validate and the on-disk path that jq actually opens.
CVE-2026-43895
jq is a command-line JSON processor. In 1.8.1 and earlier, jq accepts embedded NUL bytes in import paths at the jq-language level, but later resolves those paths through C string operations during module and data-file lookup. This creates a mismatch between the logical import string that policy or audit code may validate and the on-disk path that jq actually opens.
CVE-2026-43895
jq is a command-line JSON processor. In 1.8.1 and earlier, jq accepts embedded NUL bytes in import paths at the jq-language level, but later resolves those paths through C string operations during module and data-file lookup. This creates a mismatch between the logical import string that policy or audit code may validate and the on-disk path that jq actually opens.
CVE-2026-43895
jq: Embedded NUL in jq import paths causes local redaction-policy bypass and preserves sensitive fields in published artifacts
CVE-2026-43895
jq is a command-line JSON processor. In 1.8.1 and earlier, jq accepts ...
BDU:2026-10415
Уязвимость файла src/linker.c утилиты для обработки JSON-файлов jq, позволяющая нарушителю вызвать отказ в обслуживании
ROS-20260708-73-0056
Уязвимость jq
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-43895 jq is a command-line JSON processor. In 1.8.1 and earlier, jq accepts embedded NUL bytes in import paths at the jq-language level, but later resolves those paths through C string operations during module and data-file lookup. This creates a mismatch between the logical import string that policy or audit code may validate and the on-disk path that jq actually opens. | CVSS3: 4.4 | 0% Низкий | 3 месяца назад | |
CVE-2026-43895 jq is a command-line JSON processor. In 1.8.1 and earlier, jq accepts embedded NUL bytes in import paths at the jq-language level, but later resolves those paths through C string operations during module and data-file lookup. This creates a mismatch between the logical import string that policy or audit code may validate and the on-disk path that jq actually opens. | CVSS3: 4.4 | 0% Низкий | 3 месяца назад | |
CVE-2026-43895 jq is a command-line JSON processor. In 1.8.1 and earlier, jq accepts embedded NUL bytes in import paths at the jq-language level, but later resolves those paths through C string operations during module and data-file lookup. This creates a mismatch between the logical import string that policy or audit code may validate and the on-disk path that jq actually opens. | CVSS3: 4.4 | 0% Низкий | 3 месяца назад | |
CVE-2026-43895 jq: Embedded NUL in jq import paths causes local redaction-policy bypass and preserves sensitive fields in published artifacts | CVSS3: 4.4 | 0% Низкий | 3 месяца назад | |
CVE-2026-43895 jq is a command-line JSON processor. In 1.8.1 and earlier, jq accepts ... | CVSS3: 4.4 | 0% Низкий | 3 месяца назад | |
BDU:2026-10415 Уязвимость файла src/linker.c утилиты для обработки JSON-файлов jq, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 4.4 | 0% Низкий | 3 месяца назад | |
ROS-20260708-73-0056 Уязвимость jq | CVSS3: 4.4 | 0% Низкий | 23 дня назад |
Уязвимостей на страницу