Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

jq — Vulnerabilities & Security Advisories 23

All 23 CVE vulnerabilities found in jq, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities for the JSON processing utility jq, categorized under common weakness enumeration and associated with the jq software product. The collection encompasses various flaw types, including buffer overflows, use-after-free errors, and improper input validation issues, covering security advisories and patches released from its early public versions through the most recent stable releases. Users can utilize this resource to track the vendor’s or community’s response to specific issues over time, gain a deeper understanding of recurring weakness classes within command-line JSON tools, and look up the detailed vulnerability history of jq to assess risk exposure for their specific deployment environment. The data is organized to facilitate cross-referencing between different weakness types and release cycles, allowing security professionals to identify trends in defect introduction and resolution. By consolidating this information, the page provides a clear view of the product’s security posture without requiring manual searching across multiple external repositories. All entries are derived from verified public disclosures and official patch notes, ensuring accuracy and reliability for downstream risk assessment workflows. This centralized view helps teams prioritize updates and mitigate potential exploitation vectors effectively.

Vendor: jqlang

CVE IDTitleCVSSSeverityPublished
CVE-2026-47770 jq: stack overflow in deep structural equality CWE-674--2026-06-25
CVE-2026-49839 jq --rawfile invalid-state reuse after String too long causes heap-buffer-overflow CWE-787 7.1 High2026-06-25
CVE-2026-54679 jq: potential integer overflow in jvp_string_append CWE-190--2026-06-25
CVE-2026-43896 jq: Stack Overflow in Recursive Object Merge CWE-674 6.2 Medium2026-05-11
CVE-2026-43895 jq: Embedded NUL in jq import paths causes local redaction-policy bypass and preserves sensitive fields in published artifacts CWE-20 4.4 Medium2026-05-11
CVE-2026-44777 jq: stack overflow in module loading on mutual `include` CWE-674--2026-05-11
CVE-2026-43894 jq: Wild stack write via signed-integer overflow in decNumber D2U() macro CWE-190 6.2 Medium2026-05-11
CVE-2026-41256 jq: Embedded NUL truncates top-level jq programs loaded with -f CWE-158 5.5 Medium2026-05-11
CVE-2026-40612 jq: Stack overflow via unbounded recursion in jv_contains CWE-674--2026-05-11
CVE-2026-41257 jq: Signed-int overflow in `stack_reallocate` (jq VM stack) CWE-190--2026-05-11
CVE-2026-33948 jq: Embedded-NUL Truncation in CLI JSON Input Path Causes Prefix-Only Validation of Malformed Input CWE-170 9.8 -2026-04-13
CVE-2026-40164 jq: Algorithmic complexity DoS via hardcoded MurmurHash3 seed CWE-328 7.5 High2026-04-13
CVE-2026-39979 jq: Out-of-Bounds Read in jv_parse_sized() Error Formatting for Non-NUL-Terminated Counted Buffers CWE-125 9.8 -2026-04-13
CVE-2026-39956 jq: Missing runtime type checks for _strindices lead to crash and limited memory disclosure CWE-125 6.1 Medium2026-04-13
CVE-2026-33947 jq: Unbounded Recursion in jv_setpath(), jv_getpath() and delpaths_sorted() CWE-674 6.2 Medium2026-04-13
CVE-2026-32316 jq: Integer overflow in jvp_string_append() allows Heap-based Buffer Overflow CWE-122 8.2 High2026-04-13
CVE-2025-9403 jqlang jq JSON jq_test.c run_jq_tests assertion CWE-617 3.3 Low2025-08-25
CVE-2025-49014 jq heap use after free vulnerability in f_strflocaltime CWE-416 9.8AICriticalAI2025-06-19
CVE-2025-48060 AddressSanitizer: stack-buffer-overflow in jq_fuzz_execute (jv_string_vfmt) CWE-121 6.5AIMediumAI2025-05-21
CVE-2024-23337 jq has signed integer overflow in jv.c:jvp_array_write CWE-190 4.3 Medium2025-05-21
CVE-2024-53427 jq 安全漏洞 CWE-843 8.1 High2025-02-26
CVE-2023-50268 jq has stack-based buffer overflow in decNaNs CWE-121 6.2 Medium2023-12-13
CVE-2023-50246 jq has heap-buffer-overflow vulnerability in the function decToString in decNumber.c CWE-122 6.2 Medium2023-12-13

All 23 known CVE vulnerabilities affecting jq with full Chinese analysis, references, and POCs where available.