---
id: CVE-2026-39956
title: jq is a command-line JSON processor
summary: >-
  jq is a command-line JSON processor. Prior to version 1.8.2, the _strindices
  builtin in jq's src/builtin.c passes its arguments directly to
  jv_string_indexes() without verifying they are strings, and
  jv_string_indexes() in src/jv.c relie…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H'
cwe:
  - CWE-125
  - CWE-476
  - CWE-843
vendor: jqlang
product: jq
affected:
  - 'jq >= 2026-04-02, < 2026-04-08'
patched:
  - jq 2026-04-08
published: '2026-04-13'
updated: '2026-09-04'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-39956'
references:
  - url: >-
      https://github.com/jqlang/jq/commit/fdf8ef0f0810e3d365cdd5160de43db46f57ed03
    label: security-advisories@github.com
  - url: 'https://github.com/jqlang/jq/security/advisories/GHSA-6gc3-3g9p-xx28'
    label: security-advisories@github.com
  - url: 'https://github.com/jqlang/jq/security/advisories/GHSA-6gc3-3g9p-xx28'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00165
epssPercentile: 0.05011
ingestedAt: '2026-09-04T14:22:26.058Z'
---

## Overview

jq is a command-line JSON processor. Prior to version 1.8.2, the _strindices builtin in jq's src/builtin.c passes its arguments directly to jv_string_indexes() without verifying they are strings, and jv_string_indexes() in src/jv.c relies solely on assert() checks that are stripped in release builds compiled with -DNDEBUG. This allows an attacker to crash jq trivially with input like _strindices(0), and by crafting a numeric value whose IEEE-754 bit pattern maps to a chosen pointer, achieve a controlled pointer dereference and limited memory read/probe primitive. Any deployment that evaluates untrusted jq filters against a release build is vulnerable. This issue has been patched in commit fdf8ef0f0810e3d365cdd5160de43db46f57ed03, which is part of version 1.8.2.

## Affected

- `jq >= 2026-04-02, < 2026-04-08`

## Remediation

Upgrade past the affected range:

- `jq 2026-04-08`
