{
 "arch": "arm64",
 "findings": [
  {
   "affects": [
    "jq"
   ],
   "cvss": 7.1,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-49839",
   "severity": "high",
   "title": "jq is a command-line JSON processor. Prior to 1.8.2,` jq --rawfile` can turn a handled oversized-string error into invalid-state reuse and a real heap out-of-bounds write in assertion-disabled builds.",
   "url": "https://ubuntu.com/security/CVE-2026-49839"
  },
  {
   "affects": [
    "jq"
   ],
   "cvss": 5.5,
   "distro_severity": "negligible",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2025-9403",
   "severity": "medium",
   "title": "A vulnerability was determined in jqlang jq up to 1.6. Impacted is the function run_jq_tests of the file jq_test.c of the component JSON Parser. Executing manipulation can lead to reachable assertion. The attack requires local access.",
   "url": "https://ubuntu.com/security/CVE-2025-9403"
  },
  {
   "affects": [
    "jq"
   ],
   "cvss": 5.5,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-40612",
   "severity": "medium",
   "title": "jq is a command-line JSON processor. In 1.8.1 and earlier, jv_contains recurses into nested arrays/objects with no depth limit.",
   "url": "https://ubuntu.com/security/CVE-2026-40612"
  },
  {
   "affects": [
    "jq"
   ],
   "cvss": 5.5,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-41256",
   "severity": "medium",
   "title": "jq is a command-line JSON processor. In 1.8.1 and earlier, Top-level jq programs loaded from a file with -f are truncated at the first embedded NUL byte on current upstream HEAD. A crafted filter file such as .",
   "url": "https://ubuntu.com/security/CVE-2026-41256"
  },
  {
   "affects": [
    "jq"
   ],
   "cvss": 5.5,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-41257",
   "severity": "medium",
   "title": "jq is a command-line JSON processor. In 1.8.1 and earlier, the jq bytecode VM's data stack tracks its allocation size in a signed int.",
   "url": "https://ubuntu.com/security/CVE-2026-41257"
  },
  {
   "affects": [
    "jq"
   ],
   "cvss": 5.5,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-43894",
   "severity": "medium",
   "title": "jq is a command-line JSON processor. In 1.8.1 and earlier, when decNumberFromString is given a number literal of INT_MAX-1 (2147483646) digits, the D2U() macro overflows during signed-int arithmetic.",
   "url": "https://ubuntu.com/security/CVE-2026-43894"
  },
  {
   "affects": [
    "jq"
   ],
   "cvss": 5.5,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-43896",
   "severity": "medium",
   "title": "jq is a command-line JSON processor. In 1.8.1 and earlier, unbounded recursion in jv_object_merge_recursive() allows a crafted jq program to crash the process with a segfault.",
   "url": "https://ubuntu.com/security/CVE-2026-43896"
  },
  {
   "affects": [
    "jq"
   ],
   "cvss": 5.5,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-44777",
   "severity": "medium",
   "title": "jq is a command-line JSON processor. In 1.8.2rc1 and earlier, the ordinary module loader recurses without cycle detection when two otherwise valid modules include each other.",
   "url": "https://ubuntu.com/security/CVE-2026-44777"
  },
  {
   "affects": [
    "jq"
   ],
   "cvss": 5.5,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-47770",
   "severity": "medium",
   "title": "jq is a command-line JSON processor. Prior to 1.8.2, comparing two sufficiently deeply nested arrays with the == operator exhausts the C stack on jq's ordinary command-line surface, resulting in denial of service via stack exhaustion\u2026",
   "url": "https://ubuntu.com/security/CVE-2026-47770"
  },
  {
   "affects": [
    "jq"
   ],
   "cvss": 5.5,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-54679",
   "severity": "medium",
   "title": "jq is a command-line JSON processor. Prior to 1.8.2, on 32bit system, jvp_string_append has a chance of integer/multiple overflowing and then causing a massive buffer overrun. This vulnerability is fixed in 1.8.2.",
   "url": "https://ubuntu.com/security/CVE-2026-54679"
  },
  {
   "affects": [
    "jq"
   ],
   "cvss": 4.4,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-43895",
   "severity": "medium",
   "title": "jq is a command-line JSON processor. In 1.8.1 and earlier, jq accepts embedded NUL bytes in import paths at the jq-language level, but later resolves those paths through C string operations during module and data-file lookup.",
   "url": "https://ubuntu.com/security/CVE-2026-43895"
  }
 ],
 "findings_changed_at": "2026-08-20T16:49:35Z",
 "image": "jq",
 "inputs": {
  "sbom_sha256": "55b20d5071b66b702d8e29f37831589f18ac207c772d061ba0ef532b242a8f92"
 },
 "platform_digest": "sha256:8489c00a736dda01d70fa5789e804b2c8e49aeb138cab0703d7ad72ac9b27767",
 "project": "jq",
 "receipt_sha256": "e18962d10056f691bb6db5628c3ba337f9442319663652a3f1a4a6ddbd9c745d",
 "scanner": "grype",
 "severity_counts": {
  "critical": 0,
  "high": 1,
  "low": 0,
  "medium": 10,
  "unknown": 0
 },
 "suppressed": [],
 "version": "1.8.1",
 "vex_applied": [
  "jq-1.8.1-arm64.vex.json",
  "jq-1.8.1-arm64.ubuntu-vex.json"
 ]
}
