Improper Neutralization of Null Byte or NUL Character in jq - CVE-2026-43895

 

Improper Neutralization of Null Byte or NUL Character in jq - CVE-2026-43895

Published: May 11, 2026 / Updated: August 19, 2026


Vulnerability identifier: #VU130919
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-43895
CWE-ID: CWE-158
Exploitation vector: Local access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a local user to compromise the target system.

The vulnerability exists due to improper neutralization of null byte or NUL character in src/linker.c. A local user can cause the target application to load a different module or JSON data file than the one approved by the policy layer.


Affected software

jq
Debian Linux
openEuler
Anolis OS
Fedora
LANTIME Operating System Firmware (LTOS)
jq (Debian package)
jq-help
jq-devel
jq-debugsource
jq-debuginfo
jq
jq-doc

How to mitigate CVE-2026-43895

Install update from vendor's website.

jq - update to 1.8.2
LANTIME Operating System Firmware (LTOS) - update to 7.10.013
jq (Debian package) - update to 1.7.1-6+deb13u3
jq-help - update to 1.8.0-4
jq-devel - update to 1.8.0-4
jq-debugsource - update to 1.8.0-4
jq-debuginfo - update to 1.8.0-4
jq - update to 1.8.0-4
jq - update to 1.8.1-10
jq-doc - update to 1.8.1-10
jq-devel - update to 1.8.1-10
jq - update to 1.8.2-4.fc45

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins