Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 15 May 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 13 May 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:jqlang:jq:*:*:*:*:*:*:*:* |
Wed, 13 May 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 11 May 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jqlang
Jqlang jq |
|
| Vendors & Products |
Jqlang
Jqlang jq |
Mon, 11 May 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | jq is a command-line JSON processor. In 1.8.1 and earlier, jq accepts embedded NUL bytes in import paths at the jq-language level, but later resolves those paths through C string operations during module and data-file lookup. This creates a mismatch between the logical import string that policy or audit code may validate and the on-disk path that jq actually opens. | |
| Title | jq: Embedded NUL in jq import paths causes local redaction-policy bypass and preserves sensitive fields in published artifacts | |
| Weaknesses | CWE-158 CWE-20 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-13T14:41:03.888Z
Reserved: 2026-05-04T15:17:09.330Z
Link: CVE-2026-43895
Updated: 2026-05-13T12:49:49.846Z
Status : Analyzed
Published: 2026-05-11T18:16:37.387
Modified: 2026-05-13T17:02:10.473
Link: CVE-2026-43895
OpenCVE Enrichment
Updated: 2026-05-11T19:45:08Z