CVE-2026-44777
MediumAdvisory
Published 11 May 2026In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.5
- base score, highest
- EPSS
- 0.002
- 6th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 422
- of 17,787 indexed, latest versions
- Container images
- 336
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
The matching OSV records carry no description.
Carried by container images the latest versions of 422 of 17,787 indexed charts deploy, on 336 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| jqdeb | 1.5+dfsg-1, 1.5+dfsg-1ubuntu0.1, 1.5+dfsg-2, 1.6-1ubuntu0.20.04.1+13 more | 1.6-2.1+deb12u2, 1.7.1-6+deb13u3 | 231 |
| jqapk | 1.7.1-r0, 1.8.0-r0, 1.8.1-r0 | 1.8.2-r0 | 105 |
Charts affected
422 by stars
Container images carrying it
336 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| linuxserver/ | 9505c64720af | jq | 1.8.2-r0 | 1 |
| linuxserver/ | 7477f6455f47 | jq | no fix listed | 1 |
| linuxserver/ | 9a997426d71e | jq | no fix listed | 1 |
| linuxserver/ | 287e48152967 | jq | 1.8.2-r0 | 1 |
| linuxserver/ | 9bca08e2e6f1 | jq | 1.8.2-r0 | 1 |
| linuxserver/ | f1f23e0c9845 | jq | 1.8.2-r0 | 1 |
| linuxserver/ | c74c32408fdf | jq | 1.8.2-r0 | 1 |
| linuxserver/ | cb61ec331e80 | jq | 1.8.2-r0 | 1 |
| linuxserver/ | 4477fb1ce3ca | jq | 1.8.2-r0 | 1 |
| linuxserver/ | 2fbb21fb4903 | jq | no fix listed | 1 |
| linuxserver/ | 6108ed066d4a | jq | 1.8.2-r0 | 1 |
| linuxserver/ | 1f6f97d76e7b | jq | no fix listed | 1 |
| linuxserver/ | 2785a6ad64d3 | jq | no fix listed | 1 |
| linuxserver/ | 4a13ced2326c | jq | no fix listed | 1 |
| linuxserver/ | 4fd7a166c8f4 | jq | 1.8.2-r0 | 1 |
| linuxserver/ | 91844fa2c927 | jq | 1.8.2-r0 | 1 |
| linuxserver/ | a46d0ce0a823 | jq | 1.8.2-r0 | 1 |
| linuxserver/ | a00b6a597a38 | jq | 1.8.2-r0 | 1 |
| linuxserver/ | dd24a5f3db32 | jq | 1.8.2-r0 | 1 |
| linuxserver/ | 549c4a075496 | jq | 1.8.2-r0 | 1 |
| linuxserver/ | 2f4488c9afcd | jq | 1.8.2-r0 | 1 |
| linuxserver/ | 02bc962946fe | jq | 1.8.2-r0 | 1 |
| linuxserver/ | 5ce8c5f82f91 | jq | 1.8.2-r0 | 1 |
| linuxserver/ | 0ae315a3a456 | jq | no fix listed | 1 |
| linuxserver/ | ab105cc50322 | jq | no fix listed | 1 |
| linuxserver/ | b6ce6968ee45 | jq | no fix listed | 1 |
| linuxserver/ | bf03578ef731 | jq | 1.8.2-r0 | 1 |
| litmuschaos/ | 99961210d467 | jq | no fix listed | 1 |
| loeken/ | b940520a2236 | jq | 1.8.2-r0 | 1 |
| m11s/ | 0cd6810c9885 | jq | 1.8.2-r0 | 1 |
| mariusm/ | b3db186c3d72 | jq | 1.7.1-6+deb13u3 | 1 |
| mbround18/ | 70bd4da591cd | jq | no fix listed | 1 |
| mlikiowa/ | 1336a777f9a4 | jq | no fix listed | 1 |
| n3uronhub/ | 423a0bdd9cb9 | jq | 1.7.1-6+deb13u3 | 1 |
| natsio/ | abdc9f9f0120 | jq | 1.8.2-r0 | 1 |
| netskopeprivateaccess/ | 93e2fd164a93 | jq | no fix listed | 1 |
| nocodb/ | 4b760f0d2547 | jq | 1.8.2-r0 | 1 |
| offchainlabs/ | 9f779fa84b7b | jq | 1.6-2.1+deb12u2 | 1 |
| offchainlabs/ | e95865866129 | jq | 1.6-2.1+deb12u2 | 1 |
| oled01/ | 05d3e398e675 | jq | 1.6-2.1+deb12u2 | 1 |
| omecproject/ | 64776cb9edb3 | jq | no fix listed | 1 |
| opencsghq/ | 302c9d45d8a8 | jq | 1.6-2.1+deb12u2 | 1 |
| opencsghq/ | 04121fd19ef9 | jq | 1.6-2.1+deb12u2 | 1 |
| opencsghq/ | b6d87e1048c2 | jq | 1.6-2.1+deb12u2 | 1 |
| opendatacube/ | 91870111837c | jq | no fix listed | 1 |
| opendatacube/ | 1b90cdf68831 | jq | no fix listed | 1 |
| openwhisk/ | c80dba0de3aa | jq | no fix listed | 1 |
| owncloud/ | 51d9b74fc2a8 | jq | no fix listed | 1 |
| owncloud/ | 74c53d341076 | jq | no fix listed | 1 |
| owncloud/ | b3f9efdcd7f7 | jq | no fix listed | 1 |