
CVE-2026-40612 jq is a command-line JSON processor. In 1.8.1 and earlier, jv_contains recurses into nested arrays/objects with no depth limit. With a sufficiently nested input struc… https://www.cve.org/CVERecord?id=CVE-2026-40612
Post summary
This disclosure notes that jq 1.8.1 and earlier are vulnerable because the jv_contains function recurses without a depth limit, potentially leading to resource exhaustion.
