Improper Neutralization of Null Byte or NUL Character in jq - CVE-2026-41256
Published: April 25, 2026 / Updated: August 19, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass intended jq program integrity checks.
The vulnerability exists due to improper neutralization of null byte or NUL character in the top-level jq program compilation path when loading a jq program from a file with -f. A remote attacker can supply a crafted filter file containing an embedded NUL byte to bypass intended jq program integrity checks.
User interaction is required to run jq with the crafted filter file.
Affected software
Debian Linux
openEuler
Anolis OS
Fedora
LANTIME Operating System Firmware (LTOS)
jq (Debian package)
jq-debugsource
jq-help
jq-devel
jq-debuginfo
jq
jq-doc
How to mitigate CVE-2026-41256
LANTIME Operating System Firmware (LTOS) - update to 7.10.013
jq (Debian package) - update to 1.7.1-6+deb13u3
jq-debugsource - update to 1.8.0-4
jq-help - update to 1.8.0-4
jq-devel - update to 1.8.0-4
jq-debuginfo - update to 1.8.0-4
jq - update to 1.8.0-4
jq-doc - update to 1.8.1-9
jq-devel - update to 1.8.1-9
jq - update to 1.8.1-9
jq - update to 1.8.2-4.fc45
External References
Related Security Bulletins
- Multiple vulnerabilities in jq
- Multiple vulnerabilities in Meinberg LANTIME firmware
- Debian update for jq
- Fedora 45 update for jq
- openEuler 24.03 LTS SP3 update for jq
- openEuler 24.03 LTS update for jq
- openEuler 22.03 LTS SP4 update for jq
- openEuler 20.03 LTS SP4 update for jq
- openEuler 24.03 LTS SP1 update for jq
- Anolis OS update for jq