Improper Neutralization of Null Byte or NUL Character in jq - CVE-2026-43895
Published: May 11, 2026 / Updated: August 19, 2026
Vulnerability identifier: #VU130919
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-43895
CWE-ID: CWE-158
Exploitation vector: Local access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a local user to compromise the target system.
The vulnerability exists due to improper neutralization of null byte or NUL character in src/linker.c. A local user can cause the target application to load a different module or JSON data file than the one approved by the policy layer.
Affected software
jq
Debian Linux
openEuler
Anolis OS
Fedora
LANTIME Operating System Firmware (LTOS)
jq (Debian package)
jq-help
jq-devel
jq-debugsource
jq-debuginfo
jq
jq-doc
Debian Linux
openEuler
Anolis OS
Fedora
LANTIME Operating System Firmware (LTOS)
jq (Debian package)
jq-help
jq-devel
jq-debugsource
jq-debuginfo
jq
jq-doc
How to mitigate CVE-2026-43895
Install update from vendor's website.
jq - update to 1.8.2
LANTIME Operating System Firmware (LTOS) - update to 7.10.013
jq (Debian package) - update to 1.7.1-6+deb13u3
jq-help - update to 1.8.0-4
jq-devel - update to 1.8.0-4
jq-debugsource - update to 1.8.0-4
jq-debuginfo - update to 1.8.0-4
jq - update to 1.8.0-4
jq - update to 1.8.1-10
jq-doc - update to 1.8.1-10
jq-devel - update to 1.8.1-10
jq - update to 1.8.2-4.fc45
LANTIME Operating System Firmware (LTOS) - update to 7.10.013
jq (Debian package) - update to 1.7.1-6+deb13u3
jq-help - update to 1.8.0-4
jq-devel - update to 1.8.0-4
jq-debugsource - update to 1.8.0-4
jq-debuginfo - update to 1.8.0-4
jq - update to 1.8.0-4
jq - update to 1.8.1-10
jq-doc - update to 1.8.1-10
jq-devel - update to 1.8.1-10
jq - update to 1.8.2-4.fc45
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Improper Neutralization of Null Byte or NUL Character in jq
- Anolis OS update for jq
- Multiple vulnerabilities in Meinberg LANTIME firmware
- Debian update for jq
- Fedora 45 update for jq
- openEuler 24.03 LTS SP3 update for jq
- openEuler 24.03 LTS update for jq
- openEuler 22.03 LTS SP4 update for jq
- openEuler 20.03 LTS SP4 update for jq
- openEuler 24.03 LTS SP1 update for jq