PT-2026-39721 · Jqlang · Jq

Published

2026-05-11

·

Updated

2026-05-11

·

CVE-2026-44777

CVSS v4.0

5.3

Medium

VectorAV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
jq is a command-line JSON processor. In 1.8.2rc1 and earlier, the ordinary module loader recurses without cycle detection when two otherwise valid modules include each other.

Fix

Uncontrolled Recursion

Weakness Enumeration

Related Identifiers

CVE-2026-44777

Affected Products

Jq