VYPR

Jq

by Jqlang

Source repositories

CVEs (26)

  • CVE-2026-33948MedApr 14, 2026
    risk 0.27cvss 5.3epss 0.00

    jq is a command-line JSON processor. Commits before 6374ae0bcdfe33a18eb0ae6db28493b1f34a0a5b contain a vulnerability where CLI input parsing allows validation bypass via embedded NUL bytes. When reading JSON from files or stdin, jq uses strlen() to determine buffer length…

  • CVE-2026-43895MedMay 11, 2026
    risk 0.22cvss 4.4epss 0.00

    jq is a command-line JSON processor. In 1.8.1 and earlier, jq accepts embedded NUL bytes in import paths at the jq-language level, but later resolves those paths through C string operations during module and data-file lookup. This creates a mismatch between the logical import…

  • CVE-2025-9403LowAug 25, 2025
    risk 0.21cvss 3.3epss 0.00

    A vulnerability was determined in jqlang jq up to 1.6. Impacted is the function run_jq_tests of the file jq_test.c of the component JSON Parser. Executing manipulation can lead to reachable assertion. The attack requires local access. The exploit has been publicly disclosed and…

  • CVE-2024-23337MedMay 21, 2025
    risk 0.00cvss 4.3epss 0.00

    jq is a command-line JSON processor. In versions up to and including 1.7.1, an integer overflow arises when assigning value using an index of 2147483647, the signed integer limit. This causes a denial of service. Commit de21386681c0df0104a99d9d09db23a9b2a78b1e contains a patch…

  • CVE-2023-50268MedDec 13, 2023
    risk 0.00cvss 6.2epss 0.00

    jq is a command-line JSON processor. Version 1.7 is vulnerable to stack-based buffer overflow in builds using decNumber. Version 1.7.1 contains a patch for this issue.

  • CVE-2023-50246MedDec 13, 2023
    risk 0.00cvss 6.2epss 0.01

    jq is a command-line JSON processor. Version 1.7 is vulnerable to heap-based buffer overflow. Version 1.7.1 contains a patch for this issue.

Page 2 of 2