
CVE-2026-43895 jq is a command-line JSON processor. In 1.8.1 and earlier, jq accepts embedded NUL bytes in import paths at the jq-language level, but later resolves those paths thro… https://www.cve.org/CVERecord?id=CVE-2026-43895
Post summary
The message discloses that jq versions 1.8.1 and earlier allow embedded NUL bytes in import paths, highlighting a potential vulnerability.
