<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 11:41:40 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-10412</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-10412</link>
      <description>bdu:2026-10412</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-10412</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-40612</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-40612</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: jq, Alpaquita:25: jq, Alpaquita:stream: jq&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: jq, Alpaquita:25: jq, Alpaquita:stream: jq&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-40612</guid>
    </item>
    <item>
      <title>EUVD-2026-310033</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-310033</link>
      <description>EUVD-2026-310033</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-310033</guid>
    </item>
    <item>
      <title>fkie_cve-2026-40612</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-40612</link>
      <description>&lt;p&gt;jq is a command-line JSON processor. In 1.8.1 and earlier, jv_contains recurses into nested arrays/objects with no depth limit. With a sufficiently nested input structure (built programmatically with reduce, since the JSON parser caps at depth 10000), the C stack is exhausted.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;jq is a command-line JSON processor. In 1.8.1 and earlier, jv_contains recurses into nested arrays/objects with no depth limit. With a sufficiently nested input structure (built programmatically with reduce, since the JSON parser caps at depth 10000), the C stack is exhausted.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-40612</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-40612 — jq: Stack overflow via unbounded recursion in jv_contains</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-40612</link>
      <description>msrc_CVE-2026-40612</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-40612</guid>
    </item>
    <item>
      <title>OESA-2026-2424 — jq security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-2424</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: jq&lt;/p&gt;
&lt;p&gt;jq is a lightweight and flexible command-line JSON processor. you can use it to slice and filter and map and transform structured data. It is written in portable C, and it has zero runtime dependencies. it can mangle the data format that you have into the one that you want.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;jq is a command-line JSON processor. In 1.8.1 and earlier, jv_contains recurses into nested arrays/objects with no depth limit. With a sufficiently nested input structure (built programmatically with reduce, since the JSON parser caps at depth 10000), the C stack is exhausted.(CVE-2026-40612)&lt;/p&gt;
&lt;p&gt;jq is a command-line JSON processor. In 1.8.1 and earlier, Top-level jq programs loaded from a file with -f are truncated at the first embedded NUL byte on current upstream HEAD. A crafted filter file such as . followed by \x00 and arbitrary suffix compiles and executes as only the prefix before the NUL. This leaves jq with a post-CVE-2026-33948 prefix/full-buffer mismatch on the compilation path even though the JSON parser path has already been fixed.(CVE-2026-41256)&lt;/p&gt;
&lt;p&gt;jq is a command-line JSON processor. In 1.8.1 and earlier, the jq bytecode VM&amp;amp;apos;s data stack tracks its allocation size in a signed int. When the stack grows beyond ≈1 GiB (via deeply nested generator forks), the doubling arithmetic overflows. The wrapped value is passed to realloc and then used for a memmove with attacker-influenced offsets.(CVE-2026-41257)&lt;/p&gt;
&lt;p&gt;jq is a command-line JSON processor. In 1.8.1 and earlier, when decN…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: jq&lt;/p&gt;
&lt;p&gt;jq is a lightweight and flexible command-line JSON processor. you can use it to slice and filter and map and transform structured data. It is written in portable C, and it has zero runtime dependencies. it can mangle the data format that you have into the one that you want.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;jq is a command-line JSON processor. In 1.8.1 and earlier, jv_contains recurses into nested arrays/objects with no depth limit. With a sufficiently nested input structure (built programmatically with reduce, since the JSON parser caps at depth 10000), the C stack is exhausted.(CVE-2026-40612)&lt;/p&gt;
&lt;p&gt;jq is a command-line JSON processor. In 1.8.1 and earlier, Top-level jq programs loaded from a file with -f are truncated at the first embedded NUL byte on current upstream HEAD. A crafted filter file such as . followed by \x00 and arbitrary suffix compiles and executes as only the prefix before the NUL. This leaves jq with a post-CVE-2026-33948 prefix/full-buffer mismatch on the compilation path even though the JSON parser path has already been fixed.(CVE-2026-41256)&lt;/p&gt;
&lt;p&gt;jq is a command-line JSON processor. In 1.8.1 and earlier, the jq bytecode VM&amp;amp;apos;s data stack tracks its allocation size in a signed int. When the stack grows beyond ≈1 GiB (via deeply nested generator forks), the doubling arithmetic overflows. The wrapped value is passed to realloc and then used for a memmove with attacker-influenced offsets.(CVE-2026-41257)&lt;/p&gt;
&lt;p&gt;jq is a command-line JSON processor. In 1.8.1 and earlier, when decN…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-2424</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10850-1 — jq-1.8.1-3.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10850-1</link>
      <description>&lt;p&gt;jq-1.8.1-3.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;jq-1.8.1-3.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10850-1</guid>
    </item>
    <item>
      <title>RHSA-2026:29986 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:29986</link>
      <description>&lt;p&gt;jq: stack overflow via unbounded recursion in jv_contains jq: embedded NUL truncates top-level jq programs loaded with -f jq: signed-int overflow in stack_reallocate jq: jq: Arbitrary Code Execution or Denial of Service via Signed Integer Overflow jq: embedded NUL in jq import paths causes local redaction-policy bypass and preserves sensitive fields in published artifacts jq: stack overflow in recursive object merge jq: stack overflow in module loading on mutual include jq: jq: Denial of Service via deeply nested array comparison jq: jq: Heap out-of-bounds write via oversized raw file processing jq: jq: Denial of Service via integer overflow and buffer overrun on 32-bit systems&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;jq: stack overflow via unbounded recursion in jv_contains jq: embedded NUL truncates top-level jq programs loaded with -f jq: signed-int overflow in stack_reallocate jq: jq: Arbitrary Code Execution or Denial of Service via Signed Integer Overflow jq: embedded NUL in jq import paths causes local redaction-policy bypass and preserves sensitive fields in published artifacts jq: stack overflow in recursive object merge jq: stack overflow in module loading on mutual include jq: jq: Denial of Service via deeply nested array comparison jq: jq: Heap out-of-bounds write via oversized raw file processing jq: jq: Denial of Service via integer overflow and buffer overrun on 32-bit systems&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:29986</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:22545-1 — Security update for jq</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:22545-1</link>
      <description>&lt;p&gt;Security update for jq&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for jq&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:22545-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-40612</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-40612</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: jq, Ubuntu:Pro:16.04:LTS: jq, Ubuntu:Pro:18.04:LTS: jq, Ubuntu:Pro:20.04:LTS: jq, Ubuntu:22.04:LTS: jq, Ubuntu:24.04:LTS: jq, Ubuntu:25.10: jq, Ubuntu:26.04:LTS: jq&lt;/p&gt;
&lt;p&gt;jq is a command-line JSON processor. In 1.8.1 and earlier, jv_contains recurses into nested arrays/objects with no depth limit. With a sufficiently nested input structure (built programmatically with reduce, since the JSON parser caps at depth 10000), the C stack is exhausted.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: jq, Ubuntu:Pro:16.04:LTS: jq, Ubuntu:Pro:18.04:LTS: jq, Ubuntu:Pro:20.04:LTS: jq, Ubuntu:22.04:LTS: jq, Ubuntu:24.04:LTS: jq, Ubuntu:25.10: jq, Ubuntu:26.04:LTS: jq&lt;/p&gt;
&lt;p&gt;jq is a command-line JSON processor. In 1.8.1 and earlier, jv_contains recurses into nested arrays/objects with no depth limit. With a sufficiently nested input structure (built programmatically with reduce, since the JSON parser caps at depth 10000), the C stack is exhausted.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-40612</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1469 — jq: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1469</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in jq ausnutzen, um einen Denial of Service Angriff durchzuführen, Daten zu manipulieren oder andere, nicht näher spezifizierte Auswirkungen zu erreichen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in jq ausnutzen, um einen Denial of Service Angriff durchzuführen, Daten zu manipulieren oder andere, nicht näher spezifizierte Auswirkungen zu erreichen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1469</guid>
    </item>
  </channel>
</rss>
