Vendorsjqlangjqany version
Vulnerabilities

jqlang Jq any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

19CVEs
CVE-2026-32316
jq: Integer overflow in jvp_string_append() allows Heap-based Buffer Overflow
Published 2026-04-13 · Analyzed
8.2EPSS 0.006
CVE-2026-39979
jq: Out-of-Bounds Read in jv_parse_sized() Error Formatting for Non-NUL-Terminated Counted Buffers
Published 2026-04-13 · Modified
8.2EPSS 0.006
CVE-2024-53427
decNumberCopy in decNumber.c in jq through 1.7.1 does not properly consider that NaN is interpreted as numeric, which has a resultant stack-based buffer overflow and out-of-bounds write, as demonstrated by use of --slurp with subtraction, such as a filter of .-. when the input has a certain form of digit string with NaN (e.g., "1 NaN123" immediately followed by many more digits).
Published 2025-02-26 · Analyzed
8.1EPSS 0.004
CVE-2025-48060
AddressSanitizer: stack-buffer-overflow in jq_fuzz_execute (jv_string_vfmt)
Published 2025-05-21 · Modified
7.7EPSS 0.005
CVE-2026-49839
jq --rawfile invalid-state reuse after String too long causes heap-buffer-overflow
Published 2026-06-25 · Analyzed
7.1EPSS 0.001
CVE-2026-54679
jq: potential integer overflow in jvp_string_append
Published 2026-06-25 · Analyzed
6.9EPSS 0.001
CVE-2026-47770
jq: stack overflow in deep structural equality
Published 2026-06-25 · Analyzed
6.8EPSS 0.001
CVE-2024-23337
jq has signed integer overflow in jv.c:jvp_array_write
Published 2025-05-21 · Analyzed
6.5EPSS 0.004
CVE-2026-41257
jq: Signed-int overflow in `stack_reallocate` (jq VM stack)
Published 2026-05-11 · Analyzed
6.4EPSS 0.001
CVE-2026-33947
jq: Unbounded Recursion in jv_setpath(), jv_getpath() and delpaths_sorted()
Published 2026-04-13 · Analyzed
6.2EPSS 0.002
CVE-2026-43894
jq: Wild stack write via signed-integer overflow in decNumber D2U() macro
Published 2026-05-11 · Analyzed
6.2EPSS 0.002
CVE-2026-43896
jq: Stack Overflow in Recursive Object Merge
Published 2026-05-11 · Analyzed
6.2EPSS 0.002
CVE-2026-39956
jq: Missing runtime type checks for _strindices lead to crash and limited memory disclosure
Published 2026-04-13 · Modified
6.1EPSS 0.002
CVE-2025-9403
jqlang jq JSON jq_test.c run_jq_tests assertion
Published 2025-08-25 · Analyzed
5.5EPSS 0.002
CVE-2026-40612
jq: Stack overflow via unbounded recursion in jv_contains
Published 2026-05-11 · Analyzed
5.5EPSS 0.002
CVE-2026-44777
jq: stack overflow in module loading on mutual `include`
Published 2026-05-11 · Analyzed
5.5EPSS 0.002
CVE-2026-41256
jq: Embedded NUL truncates top-level jq programs loaded with -f
Published 2026-05-11 · Analyzed
5.5EPSS 0.002
CVE-2026-33948
jq: Embedded-NUL Truncation in CLI JSON Input Path Causes Prefix-Only Validation of Malformed Input
Published 2026-04-13 · Analyzed
5.3EPSS 0.003
CVE-2026-43895
jq: Embedded NUL in jq import paths causes local redaction-policy bypass and preserves sensitive fields in published artifacts
Published 2026-05-11 · Analyzed
4.4EPSS 0.002