Skip to content
Multiple jq Vulnerabilities in Ubuntu 26.04 LTS Lead to DoS and Code Execution Risks

Multiple jq Vulnerabilities in Ubuntu 26.04 LTS Lead to DoS and Code Execution Risks

First seen 28 Apr 2026, 11:33 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster April 29, 2026 at 11:31 UTC
  • Multiple vulnerabilities in jq could lead to denial of service or arbitrary code execution.
  • Affected versions include Ubuntu 26.04 LTS and its derivatives.
  • Users should update their systems to the latest package versions to mitigate risks.

On April 28, 2026, Ubuntu released USN-8202-2 addressing several vulnerabilities in jq, a command-line JSON processor. These vulnerabilities include improper handling of string concatenations (CVE-2026-32316), recursion (CVE-2026-33947), improperly terminated strings (CVE-2026-33948), and variable type checking (CVE-2026-39956). Attackers could exploit these issues to cause denial of service or execute arbitrary code. The vulnerabilities were published on April 13, 2026, and affect Ubuntu 26.04 LTS and its derivatives. Users are advised to update their systems to mitigate these risks. The vulnerabilities could potentially lead to sensitive information leaks or service disruptions. The patch is available as part of a standard system update.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 144d ago How this analysis works

Timeline

2026-04-13
CVE-2026-32316, CVE-2026-33947, CVE-2026-33948, CVE-2026-39956 published
2026-04-13
CVE-2026-40164 published
2026-04-13
CVE-2026-39979 published
2026-04-28
USN-8202-2 released to address jq vulnerabilities

More articles in this cluster (2)

Following this threat?

Track Ubuntu and CVE-2026-32316 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed