MEDIUM🇬🇧 English

CVE-2026-41256

CVSS 5.5v3.1pub. 2026-05-11upd. 2026-05-13

jq to procesor JSON obsługiwany z wiersza poleceń. W wersji 1.8.1 i starszych programy jq na najwyższym poziomie wczytane z pliku za pomocą -f są obcinane przy pierwszym osadzonym bajcie NUL. Crafted plik filtra taki jak . następnie \x00 i dowolny sufiks kompiluje się i wykonuje tylko jako prefiks przed bajtami NUL. Pozostawia to jq z niezgodnością prefix/full-buffer na ścieżce kompilacji nawet jeśli ścieżka parsera JSON została już naprawiona.

Pokaż oryginał (EN)

jq is a command-line JSON processor. In 1.8.1 and earlier, Top-level jq programs loaded from a file with -f are truncated at the first embedded NUL byte on current upstream HEAD. A crafted filter file such as . followed by \x00 and arbitrary suffix compiles and executes as only the prefix before the NUL. This leaves jq with a post-CVE-2026-33948 prefix/full-buffer mismatch on the compilation path even though the JSON parser path has already been fixed.

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
  • Jqlang Jq

    APP
    Jqlang
    ≤ 1.8.1
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2026-49839HIGH7.1PL ✓ten sam produkt

jq: heap out-of-bounds write przez --rawfile przy zbyt długim pliku

CVE-2026-32316HIGH8.2ten sam produkt

jq is a command-line JSON processor. An integer overflow vulnerability exists through version 1.8.1 within the...

CVE-2025-48060HIGH7.7ten sam produkt

jq is a command-line JSON processor. In versions up to and including 1.7.1, a heap-buffer-overflow is present ...

CVE-2024-53427HIGH8.1ten sam produkt

decNumberCopy in decNumber.c in jq through 1.7.1 does not properly consider that NaN is interpreted as numeric...

CVE-2023-49355HIGH7.5ten sam produkt

decToString in decNumber/decNumber.c in jq 88f01a7 has a one-byte out-of-bounds write via the " []-1.2e-111111...