CVE-2026-40612
MediumAdvisory
Published 11 May 2026In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.5
- base score, highest
- EPSS
- 0.002
- 6th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 428
- of 17,781 indexed, latest versions
- Container images
- 341
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
The matching OSV records carry no description.
Carried by container images the latest versions of 428 of 17,781 indexed charts deploy, on 341 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| jqdeb | 1.5+dfsg-1, 1.5+dfsg-1ubuntu0.1, 1.5+dfsg-2, 1.6-1ubuntu0.20.04.1+14 more | 1.7.1-6+deb13u3 | 236 |
| jqapk | 1.7.1-r0, 1.8.0-r0, 1.8.1-r0 | 1.8.2-r0 | 105 |
Charts affected
428 by stars
Container images carrying it
341 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| library/ | 5211c51171f5 | jq | no fix listed | 12 |
| oomk8s/ | 875814cc853d | jq | no fix listed | 11 |
| library/ | 8e70544b6c76 | jq | no fix listed | 10 |
| oomk8s/ | 7daa08b81954 | jq | no fix listed | 6 |
| bitnamilegacy/ | c74b703deed2 | jq | no fix listed | 5 |
| library/ | 4be76f674fc4 | jq | no fix listed | 5 |
| hyperledger/ | 4ce6f43ded2e | jq | no fix listed | 4 |
| library/ | 5e15a3f014ed | jq | no fix listed | 4 |
| library/ | 628741415fc9 | jq | no fix listed | 4 |
| library/ | 6efa05203990 | jq | no fix listed | 4 |
| linuxserver/ | 4d9df314875e | jq | 1.8.2-r0 | 4 |
| pihole/ | f7d1be836e3b | jq | 1.8.2-r0 | 4 |
| ghcr.io/ | 7f9a1d574958 | jq | no fix listed | 4 |
| bitnamilegacy/ | cd354d5b2556 | jq | no fix listed | 3 |
| bitnamilegacy/ | 77e65e9d633e | jq | no fix listed | 3 |
| dgraph/ | 3b55ea83fffe | jq | no fix listed | 3 |
| gchq/ | 5ec58edbb2db | jq | no fix listed | 3 |
| natsio/ | 8031d190c7ee | jq | 1.8.2-r0 | 3 |
| natsio/ | ffce8bd10338 | jq | 1.8.2-r0 | 3 |
| selenium/ | 02f251d48d5f | jq | no fix listed | 3 |
| quay.io/ | ae9ea21f7427 | jq | no fix listed | 3 |
| quay.io/ | 2b6db27eaf3d | jq | no fix listed | 3 |
| quay.io/ | 522738d5285e | jq | 1.8.2-r0 | 3 |
| alpine/ | 048f8d9c8cc7 | jq | 1.8.2-r0 | 2 |
| apache/ | 7cdfd8deec92 | jq | no fix listed | 2 |
| cribl/ | 044f9a5fac9a | jq | no fix listed | 2 |
| gisaia/ | 3700dcaf7a75 | jq | 1.8.2-r0 | 2 |
| gisaia/ | b83b3e067173 | jq | 1.8.2-r0 | 2 |
| gisaia/ | a35977a5bb7d | jq | 1.8.2-r0 | 2 |
| gisaia/ | 1a3cc43d822f | jq | 1.8.2-r0 | 2 |
| homebridge/ | 77c685a40911 | jq | no fix listed | 2 |
| jupyterhub/ | 69a7170eeeda | jq | 1.8.2-r0 | 2 |
| library/ | 098862b1339f | jq | no fix listed | 2 |
| library/ | 406a4fdca9fc | jq | no fix listed | 2 |
| library/ | 41108d183e97 | jq | no fix listed | 2 |
| library/ | 58b25d51baa1 | jq | no fix listed | 2 |
| library/ | 81a1c8842a09 | jq | no fix listed | 2 |
| library/ | b096b4cb9269 | jq | no fix listed | 2 |
| library/ | b6421fd6d1c5 | jq | no fix listed | 2 |
| linuxserver/ | 6468911d00b1 | jq | 1.8.2-r0 | 2 |
| linuxserver/ | 609a1830692d | jq | 1.8.2-r0 | 2 |
| mesosphere/ | ea01a9387771 | jq | 1.8.2-r0 | 2 |
| wolveix/ | e103700ae6ae | jq | no fix listed | 2 |
| ghcr.io/ | 4249e403225a | jq | 1.8.2-r0 | 2 |
| ghcr.io/ | f115777d1112 | jq | 1.8.2-r0 | 2 |
| ghcr.io/ | c137478627cc | jq | 1.8.2-r0 | 2 |
| ghcr.io/ | 612d76760b54 | jq | 1.8.2-r0 | 2 |
| ghcr.io/ | a1bc133af84e | jq | 1.8.2-r0 | 2 |
| ghcr.io/ | 0ebb4ae26ee9 | jq | 1.8.2-r0 | 2 |
| ghcr.io/ | 8f7551205fbd | jq | 1.8.2-r0 | 2 |