CVE-2026-41257
MediumAdvisory
Published 11 May 2026In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.5
- base score, highest
- EPSS
- 0.001
- 4th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 422
- of 17,787 indexed, latest versions
- Container images
- 336
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
The matching OSV records carry no description.
Carried by container images the latest versions of 422 of 17,787 indexed charts deploy, on 336 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| jqdeb | 1.5+dfsg-1, 1.5+dfsg-1ubuntu0.1, 1.5+dfsg-2, 1.6-1ubuntu0.20.04.1+13 more | 1.6-2.1+deb12u2, 1.7.1-6+deb13u3 | 231 |
| jqapk | 1.7.1-r0, 1.8.0-r0, 1.8.1-r0 | 1.8.2-r0 | 105 |
Charts affected
422 by stars
Container images carrying it
336 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| falcosecurity/ | 7df783d5269a | jq | 1.6-2.1+deb12u2 | 1 |
| filebrowser/ | dbac07403040 | jq | 1.8.2-r0 | 1 |
| filiparag/ | 5a9cbae7997c | jq | 1.8.2-r0 | 1 |
| fluent/ | e76397ef3983 | jq | 1.6-2.1+deb12u2 | 1 |
| free5gmano/ | 36f806935519 | jq | no fix listed | 1 |
| gradiant/ | 332031245fce | jq | no fix listed | 1 |
| haugene/ | 059216cfae4b | jq | no fix listed | 1 |
| haveagitgat/ | 3ff0913202dd | jq | no fix listed | 1 |
| homeassistant/ | 5a531753cea9 | jq | 1.8.2-r0 | 1 |
| hyperglance/ | 467ad8491bc3 | jq | no fix listed | 1 |
| hyperglance/ | 9fd5faf1fe80 | jq | no fix listed | 1 |
| hyperglance/ | b2f8c6d52623 | jq | no fix listed | 1 |
| ibmcom/ | 7e4dc1e27cdf | jq | no fix listed | 1 |
| improwised/ | 28940522e8b7 | jq | 1.6-2.1+deb12u2 | 1 |
| itzg/ | 4e29d14082d9 | jq | no fix listed | 1 |
| itzg/ | 8672e335dbef | jq | no fix listed | 1 |
| ixsystems/ | 19c218455cd2 | jq | 1.7.1-6+deb13u3 | 1 |
| jertel/ | 3cbf63f9b7dc | jq | 1.7.1-6+deb13u3 | 1 |
| jmferrer/ | 030f68ec6998 | jq | no fix listed | 1 |
| jordan/ | f75025fe8ea8 | jq | 1.6-2.1+deb12u2 | 1 |
| josh5/ | 4d49c4816260 | jq | no fix listed | 1 |
| kubeoperator/ | be8f0d624640 | jq | no fix listed | 1 |
| kubeshop/ | d48b172d99d8 | jq | no fix listed | 1 |
| lancachenet/ | 37f28b362c93 | jq | no fix listed | 1 |
| library/ | 0032d2ca20db | jq | no fix listed | 1 |
| library/ | 02a0cc7939f5 | jq | no fix listed | 1 |
| library/ | 05678ae4e5e1 | jq | no fix listed | 1 |
| library/ | 146c1fd999a6 | jq | no fix listed | 1 |
| library/ | 3b6c281e1c08 | jq | no fix listed | 1 |
| library/ | 3d0e6df9fd5b | jq | no fix listed | 1 |
| library/ | 50cae5081ab4 | jq | no fix listed | 1 |
| library/ | 646902910d6a | jq | no fix listed | 1 |
| library/ | 699d652ed674 | jq | no fix listed | 1 |
| library/ | 6ca49afbcb2b | jq | no fix listed | 1 |
| library/ | 6ede2806c78e | jq | no fix listed | 1 |
| library/ | 71a63fc2438e | jq | no fix listed | 1 |
| library/ | 7c81758cb295 | jq | no fix listed | 1 |
| library/ | 88785f6f665a | jq | no fix listed | 1 |
| library/ | 9cb28f7291d9 | jq | no fix listed | 1 |
| library/ | ae1cf99fa7bf | jq | no fix listed | 1 |
| library/ | d23ec07162ca | jq | no fix listed | 1 |
| library/ | dca8d11fe467 | jq | no fix listed | 1 |
| library/ | 2caf944aa4a5 | jq | 1.7.1-6+deb13u3 | 1 |
| library/ | 5ab4ab0358cf | jq | 1.7.1-6+deb13u3 | 1 |
| library/ | 6c162e2432f8 | jq | 1.7.1-6+deb13u3 | 1 |
| linuxserver/ | a20fb11a440d | jq | 1.8.2-r0 | 1 |
| linuxserver/ | 2ebf97852661 | jq | 1.8.2-r0 | 1 |
| linuxserver/ | a847b5b2d860 | jq | no fix listed | 1 |
| linuxserver/ | 241009026e6f | jq | no fix listed | 1 |
| linuxserver/ | a5e43a05ae79 | jq | no fix listed | 1 |