Main
Vulnerability Database
Exploits
ID:12577 - Exploit for NULL pointer dereference in jq - CVE-2026-39956
ID:12577 - Exploit for NULL pointer dereference in jq - CVE-2026-39956
Published: April 13, 2026
Vulnerability identifier: #VU125840
Vulnerability risk: Medium
CVE-ID: CVE-2026-39956
CWE-ID: CWE-476
Exploitation vector: Remote access
Vulnerable software:
jq
jq
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to jq _strindices missing runtime type checks. A remote attacker can pass specially crafted data to the application and perform a denial of service (DoS) attack or gain access to sensitive information.
Remediation
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.