CVE-2026-41256
MediumAdvisory
Published 11 May 2026In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.5
- base score, highest
- EPSS
- 0.002
- 5th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 423
- of 17,781 indexed, latest versions
- Container images
- 336
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
The matching OSV records carry no description.
Carried by container images the latest versions of 423 of 17,781 indexed charts deploy, on 336 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| jqdeb | 1.5+dfsg-1, 1.5+dfsg-1ubuntu0.1, 1.5+dfsg-2, 1.6-1ubuntu0.20.04.1+13 more | 1.6-2.1+deb12u2, 1.7.1-6+deb13u3 | 231 |
| jqapk | 1.7.1-r0, 1.8.0-r0, 1.8.1-r0 | 1.8.2-r0 | 105 |
Charts affected
423 by stars
Container images carrying it
336 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| registry.gitlab.com/ | b1198ea741d1 | jq | 1.8.2-r0 | 2 |
| 48n6e/ | a6ed886fddfc | jq | 1.6-2.1+deb12u2 | 1 |
| adwerx/ | 840d2b078682 | jq | no fix listed | 1 |
| airbyte/ | 98d2c39d512e | jq | 1.6-2.1+deb12u2 | 1 |
| alpine/ | 44ef4942e171 | jq | 1.8.2-r0 | 1 |
| alpine/ | 6dbe6f391eda | jq | 1.8.2-r0 | 1 |
| alpine/ | 7a319b15cfc9 | jq | 1.8.2-r0 | 1 |
| alpine/ | b7a12c5ddf26 | jq | 1.8.2-r0 | 1 |
| alpine/ | d870622d0040 | jq | 1.8.2-r0 | 1 |
| antiantiops/ | eeff80a99d92 | jq | no fix listed | 1 |
| antrea/ | c10bc45c6272 | jq | no fix listed | 1 |
| apache/ | 63b8e3e40742 | jq | no fix listed | 1 |
| aquasec/ | 7a8fa32dce21 | jq | 1.8.2-r0 | 1 |
| aristidetm/ | 469dbc951224 | jq | 1.6-2.1+deb12u2 | 1 |
| arunvelsriram/ | 655ad18fd8d6 | jq | no fix listed | 1 |
| assistiot/ | d157fbe150e3 | jq | no fix listed | 1 |
| atlassian/ | 4af4bb6c8d46 | jq | no fix listed | 1 |
| berkeleyskypilot/ | 3bc8bf8f4d83 | jq | 1.7.1-6+deb13u3 | 1 |
| berkeleyskypilot/ | 8da2f3cda472 | jq | 1.7.1-6+deb13u3 | 1 |
| bitnamilegacy/ | 1249fc292e84 | jq | 1.6-2.1+deb12u2 | 1 |
| bitnamilegacy/ | 64614ef8290f | jq | 1.6-2.1+deb12u2 | 1 |
| bitnamilegacy/ | 744f84cf7493 | jq | 1.6-2.1+deb12u2 | 1 |
| bitnamilegacy/ | f5fc0d561d9e | jq | 1.6-2.1+deb12u2 | 1 |
| bitnamilegacy/ | 5501c419f42e | jq | 1.6-2.1+deb12u2 | 1 |
| bitnamilegacy/ | 6dabb4a2088c | jq | 1.6-2.1+deb12u2 | 1 |
| bitnamilegacy/ | 8935e75fa5d1 | jq | 1.6-2.1+deb12u2 | 1 |
| bitnamilegacy/ | 952f86d1116c | jq | 1.6-2.1+deb12u2 | 1 |
| bitnamilegacy/ | ba9f3b4b0b00 | jq | 1.6-2.1+deb12u2 | 1 |
| bitnamilegacy/ | c0ede65eb88e | jq | 1.6-2.1+deb12u2 | 1 |
| bitnamilegacy/ | cce234b4381a | jq | 1.6-2.1+deb12u2 | 1 |
| bitnamilegacy/ | d7cd0e172c4c | jq | 1.6-2.1+deb12u2 | 1 |
| bitnamilegacy/ | 17444b4b2c96 | jq | 1.6-2.1+deb12u2 | 1 |
| bitnamilegacy/ | 9ba5d16f9c64 | jq | 1.6-2.1+deb12u2 | 1 |
| bitnamilegacy/ | d24925821dd2 | jq | 1.6-2.1+deb12u2 | 1 |
| bitnamilegacy/ | e328cff6e450 | jq | 1.6-2.1+deb12u2 | 1 |
| blackducksoftware/ | 90cca32de2cc | jq | 1.8.2-r0 | 1 |
| blackducksoftware/ | 8f422b18d171 | jq | 1.8.2-r0 | 1 |
| budibase/ | 44fe6feab985 | jq | 1.8.2-r0 | 1 |
| budibase/ | 8d780b6ee602 | jq | 1.7.1-6+deb13u3 | 1 |
| budibase/ | de5e2e560ce8 | jq | 1.8.2-r0 | 1 |
| cheveo/ | 82240f890884 | jq | no fix listed | 1 |
| circleci/ | 9bdc62f02162 | jq | no fix listed | 1 |
| cribl/ | 762747cb6796 | jq | no fix listed | 1 |
| dependencytrack/ | 00560b57a6cf | jq | 1.8.2-r0 | 1 |
| dependencytrack/ | 8854a8320475 | jq | 1.8.2-r0 | 1 |
| dgraph/ | b57fa31f9b7f | jq | no fix listed | 1 |
| dobtc/ | a870f7cb1105 | jq | 1.6-2.1+deb12u2 | 1 |
| eginnovations/ | e4dfe242fe9f | jq | no fix listed | 1 |
| escaping/ | 87fa79255962 | jq | 1.7.1-6+deb13u3 | 1 |
| ethpandaops/ | 1efa2fba6711 | jq | 1.7.1-6+deb13u3 | 1 |