CVE-2026-43896

EUVD-2026-29174
jq is a command-line JSON processor. In 1.8.1 and earlier, unbounded recursion in jv_object_merge_recursive() allows a crafted jq program to crash the process with a segfault. The function is reachable through the * operator when both operands are objects.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.2 MEDIUM
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 5.07%
Affected Products (NVD)
VendorProductVersion
jqlangjq
𝑥
≤ 1.8.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
jq
bookworm
1.6-2.1+deb12u2
fixed
bookworm (security)
1.6-2.1+deb12u2
fixed
bullseye
vulnerable
bullseye (security)
1.6-2.1+deb11u3
fixed
forky
1.8.2-1
fixed
sid
1.8.2-1
fixed
trixie
vulnerable
trixie (security)
1.7.1-6+deb13u3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
jq
bionic
needed
focal
needed
jammy
needed
noble
needed
questing
ignored
resolute
needed
trusty
needed
xenial
ignored
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
jq
Amazon Linux 2
0:1.6-17.amzn2.0.1
fixed
Amazon Linux 2023
0:1.8.1-59.amzn2023
fixed
jq-debuginfo
Amazon Linux 2
0:1.6-17.amzn2.0.1
fixed
Amazon Linux 2023
0:1.8.1-59.amzn2023
fixed
jq-debugsource
Amazon Linux 2023
0:1.8.1-59.amzn2023
fixed
jq-devel
Amazon Linux 2
0:1.6-17.amzn2.0.1
fixed
Amazon Linux 2023
0:1.8.1-59.amzn2023
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
jq
Azure Linux 3.0
0:1.7.1-6.azl3
fixed