CVE-2026-39956 | jqlang jq src/builtin.c jv_string_indexes out-of-bounds (GHSA-6gc3-3g9p-xx28)
A vulnerability has been found in jqlang jq and classified as problematic. Impacted is the function jv_string_indexes of the file src/builtin.c. This manipulation causes out-of-bounds read.
This vulnerability is handled as CVE-2026-39956. It is possible to launch the attack on the local host. There is not any exploit available.
It is suggested to install a patch to address this issue.