A vulnerability in the open-source JSON processor `jq` (CVE not yet assigned) enables an unspecified remote attack vector, scoring a CVSS base score of 7.3 (High). The advisory lists affected operating systems as Linux, other UNIX, and Windows, but does not specify vulnerable or fixed software versions. No patch or mitigation is currently available.
[WID-SEC-2026-1927] jq: Schwachstelle ermöglicht nicht spezifizierten Angriff CVSS Base Score 7.3 (hoch) CVSS Temporal Score 6.7 (mittel) Remoteangriff ja Datum 15.06.2026 Stand 16.06.2026 Mitigation nein Betroffene Systeme Betriebssystem Linux Sonstiges UNIX Windows Produktbeschreibung Open Source jq ist ein Kommandozeilen-JSON-Prozessor. Produkte 15.06.2026 Open Source jq Angriff Angriff Ein Angreifer kann eine Schwachstelle in jq ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen. CVE Informationen Versionshistorie Feedback zum Advisory geben