5.4
/ 10
MEDIUM
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P
Description
jq is a command-line JSON processor. In 1.8.2rc1 and earlier, the ordinary module loader recurses without cycle detection when two
otherwise valid modules include each other.
otherwise valid modules include each other.
Basic Information
ID
CVE-2026-44777
Source
GitHub_M
Published
May 11, 2026 at 17:23
Affected Product
Vendor
jqlang
Product
jq
Version
<= 1.8.2rc1
Affected Versions
jqlang jq <= 1.8.2rc1