{"id":"CVE-2026-39956","title":"jq is a command-line JSON processor","summary":"jq is a command-line JSON processor. Prior to version 1.8.2, the _strindices builtin in jq's src/builtin.c passes its arguments directly to jv_string_indexes() without verifying they are strings, and jv_string_indexes() in src/jv.c relie…","severity":"medium","cvss":6.1,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","cwe":["CWE-125","CWE-476","CWE-843"],"vendor":"jqlang","product":"jq","affected":["jq >= 2026-04-02, < 2026-04-08"],"patched":["jq 2026-04-08"],"published":"2026-04-13","updated":"2026-09-04","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-39956","references":[{"url":"https://github.com/jqlang/jq/commit/fdf8ef0f0810e3d365cdd5160de43db46f57ed03","label":"security-advisories@github.com"},{"url":"https://github.com/jqlang/jq/security/advisories/GHSA-6gc3-3g9p-xx28","label":"security-advisories@github.com"},{"url":"https://github.com/jqlang/jq/security/advisories/GHSA-6gc3-3g9p-xx28","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd"],"epss":0.00165,"epssPercentile":0.04983,"ingestedAt":"2026-09-04T14:22:26.058Z","slug":"CVE-2026-39956","body":"## Overview\n\njq is a command-line JSON processor. Prior to version 1.8.2, the _strindices builtin in jq's src/builtin.c passes its arguments directly to jv_string_indexes() without verifying they are strings, and jv_string_indexes() in src/jv.c relies solely on assert() checks that are stripped in release builds compiled with -DNDEBUG. This allows an attacker to crash jq trivially with input like _strindices(0), and by crafting a numeric value whose IEEE-754 bit pattern maps to a chosen pointer, achieve a controlled pointer dereference and limited memory read/probe primitive. Any deployment that evaluates untrusted jq filters against a release build is vulnerable. This issue has been patched in commit fdf8ef0f0810e3d365cdd5160de43db46f57ed03, which is part of version 1.8.2.\n\n## Affected\n\n- `jq >= 2026-04-02, < 2026-04-08`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `jq 2026-04-08`","depth":"sunlit","depthScore":34,"depthScoreParts":{"impact":33.6,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}