{
 "scanner": "grype",
 "at": "2026-08-19T12:22:41Z",
 "arch": "arm64",
 "findings": [
  {
   "id": "CVE-2026-49839",
   "severity": "high",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 7.1,
   "affects": [
    "jq"
   ],
   "title": "jq is a command-line JSON processor. Prior to 1.8.2,` jq --rawfile` can turn a handled oversized-string error into invalid-state reuse and a real heap out-of-bounds write in assertion-disabled builds.",
   "url": "https://ubuntu.com/security/CVE-2026-49839"
  },
  {
   "id": "CVE-2025-9403",
   "severity": "medium",
   "distro_severity": "negligible",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 5.5,
   "affects": [
    "jq"
   ],
   "title": "A vulnerability was determined in jqlang jq up to 1.6. Impacted is the function run_jq_tests of the file jq_test.c of the component JSON Parser. Executing manipulation can lead to reachable assertion. The attack requires local access.",
   "url": "https://ubuntu.com/security/CVE-2025-9403"
  },
  {
   "id": "CVE-2026-40612",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 5.5,
   "affects": [
    "jq"
   ],
   "title": "jq is a command-line JSON processor. In 1.8.1 and earlier, jv_contains recurses into nested arrays/objects with no depth limit.",
   "url": "https://ubuntu.com/security/CVE-2026-40612"
  },
  {
   "id": "CVE-2026-41256",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 5.5,
   "affects": [
    "jq"
   ],
   "title": "jq is a command-line JSON processor. In 1.8.1 and earlier, Top-level jq programs loaded from a file with -f are truncated at the first embedded NUL byte on current upstream HEAD. A crafted filter file such as .",
   "url": "https://ubuntu.com/security/CVE-2026-41256"
  },
  {
   "id": "CVE-2026-41257",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 5.5,
   "affects": [
    "jq"
   ],
   "title": "jq is a command-line JSON processor. In 1.8.1 and earlier, the jq bytecode VM's data stack tracks its allocation size in a signed int.",
   "url": "https://ubuntu.com/security/CVE-2026-41257"
  },
  {
   "id": "CVE-2026-43894",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 5.5,
   "affects": [
    "jq"
   ],
   "title": "jq is a command-line JSON processor. In 1.8.1 and earlier, when decNumberFromString is given a number literal of INT_MAX-1 (2147483646) digits, the D2U() macro overflows during signed-int arithmetic.",
   "url": "https://ubuntu.com/security/CVE-2026-43894"
  },
  {
   "id": "CVE-2026-43896",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 5.5,
   "affects": [
    "jq"
   ],
   "title": "jq is a command-line JSON processor. In 1.8.1 and earlier, unbounded recursion in jv_object_merge_recursive() allows a crafted jq program to crash the process with a segfault.",
   "url": "https://ubuntu.com/security/CVE-2026-43896"
  },
  {
   "id": "CVE-2026-44777",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 5.5,
   "affects": [
    "jq"
   ],
   "title": "jq is a command-line JSON processor. In 1.8.2rc1 and earlier, the ordinary module loader recurses without cycle detection when two otherwise valid modules include each other.",
   "url": "https://ubuntu.com/security/CVE-2026-44777"
  },
  {
   "id": "CVE-2026-47770",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 5.5,
   "affects": [
    "jq"
   ],
   "title": "jq is a command-line JSON processor. Prior to 1.8.2, comparing two sufficiently deeply nested arrays with the == operator exhausts the C stack on jq's ordinary command-line surface, resulting in denial of service via stack exhaustion\u2026",
   "url": "https://ubuntu.com/security/CVE-2026-47770"
  },
  {
   "id": "CVE-2026-54679",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 5.5,
   "affects": [
    "jq"
   ],
   "title": "jq is a command-line JSON processor. Prior to 1.8.2, on 32bit system, jvp_string_append has a chance of integer/multiple overflowing and then causing a massive buffer overrun. This vulnerability is fixed in 1.8.2.",
   "url": "https://ubuntu.com/security/CVE-2026-54679"
  },
  {
   "id": "CVE-2026-43895",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 4.4,
   "affects": [
    "jq"
   ],
   "title": "jq is a command-line JSON processor. In 1.8.1 and earlier, jq accepts embedded NUL bytes in import paths at the jq-language level, but later resolves those paths through C string operations during module and data-file lookup.",
   "url": "https://ubuntu.com/security/CVE-2026-43895"
  }
 ],
 "severity_counts": {
  "critical": 0,
  "high": 1,
  "medium": 10,
  "low": 0,
  "unknown": 0
 },
 "suppressed": []
}
