Improper Neutralization of Null Byte or NUL Character in jq - CVE-2026-41256

 

Improper Neutralization of Null Byte or NUL Character in jq - CVE-2026-41256

Published: April 25, 2026 / Updated: August 19, 2026


Vulnerability identifier: #VU127878
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-41256
CWE-ID: CWE-158
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass intended jq program integrity checks.

The vulnerability exists due to improper neutralization of null byte or NUL character in the top-level jq program compilation path when loading a jq program from a file with -f. A remote attacker can supply a crafted filter file containing an embedded NUL byte to bypass intended jq program integrity checks.

User interaction is required to run jq with the crafted filter file.


Affected software

jq
Debian Linux
openEuler
Anolis OS
Fedora
LANTIME Operating System Firmware (LTOS)
jq (Debian package)
jq-debugsource
jq-help
jq-devel
jq-debuginfo
jq
jq-doc

How to mitigate CVE-2026-41256

Install update from vendor's website.

jq - update to 1.8.2
LANTIME Operating System Firmware (LTOS) - update to 7.10.013
jq (Debian package) - update to 1.7.1-6+deb13u3
jq-debugsource - update to 1.8.0-4
jq-help - update to 1.8.0-4
jq-devel - update to 1.8.0-4
jq-debuginfo - update to 1.8.0-4
jq - update to 1.8.0-4
jq-doc - update to 1.8.1-9
jq-devel - update to 1.8.1-9
jq - update to 1.8.1-9
jq - update to 1.8.2-4.fc45

External References

Related Security Bulletins