Medium severity5.5NVD Advisory· Published May 11, 2026· Updated Jun 17, 2026
CVE-2026-44777
CVE-2026-44777
Description
jq is a command-line JSON processor. In 1.8.2rc1 and earlier, the ordinary module loader recurses without cycle detection when two otherwise valid modules include each other.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- osv-coords2 versions
< 1.7.1-160000.4.1+ 1 more
- (no CPE)range: < 1.7.1-160000.4.1
- (no CPE)range: < 1.8.1-3.1
Patches
Vulnerability mechanics
References
1- github.com/jqlang/jq/security/advisories/GHSA-rmpv-jgvr-wpr9nvdExploitMitigationVendor Advisory
News mentions
0No linked articles in our index yet.