CVE-2026-44777

EUVD-2026-29177
jq is a command-line JSON processor. In 1.8.2rc1 and earlier, the ordinary module loader recurses without cycle detection when two
otherwise valid modules include each other.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 5.72%
Affected Products (NVD)
VendorProductVersion
jqlangjq
𝑥
≤ 1.8.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
jq
bookworm
1.6-2.1+deb12u2
fixed
bookworm (security)
1.6-2.1+deb12u2
fixed
bullseye
vulnerable
bullseye (security)
1.6-2.1+deb11u3
fixed
forky
1.8.2-1
fixed
sid
1.8.2-1
fixed
trixie
vulnerable
trixie (security)
1.7.1-6+deb13u3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
jq
bionic
needed
focal
needed
jammy
needed
noble
needed
questing
ignored
resolute
needed
trusty
needed
xenial
ignored
Azure Linux logo
Azure Linux Releases
Azure Package
Release
jq
Azure Linux 3.0
0:1.7.1-6.azl3
fixed