jq
jqlang- Product type
- Other
- Catalog vulnerabilities
- 24
Severity across 23 analyzed records
en
Verify to analyze this security profile
As of 09/14/2026, within CyStack's analyzed data, jq has 3 security vulnerabilities published in the last 90 days. Of these, 1 is rated High or Critical. None of these vulnerabilities is listed in the CISA KEV catalog. CyStack recommends that organizations and individual users remediate applicable vulnerabilities as soon as possible.
CyStack does not yet have sufficient official-source data to identify the latest version of jq and determine which vulnerabilities affect that version.
| Vulnerability | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-47770jq: stack overflow in deep structural equality | Exploitation statusNot known exploited | FixYes | Published06/25/2026 | SeverityMedium |
CVE-2026-49839jq --rawfile invalid-state reuse after String too long causes heap-buffer-overflow | Exploitation statusPublic exploit | FixYes | Published06/25/2026 | SeverityHigh |
CVE-2026-54679jq: potential integer overflow in jvp_string_append | Exploitation statusNot known exploited | FixYes | Published06/25/2026 | SeverityMedium |
CVE-2026-43896jq: Stack Overflow in Recursive Object Merge | Exploitation statusPublic exploit | FixNot confirmed | Published05/11/2026 | SeverityMedium |
CVE-2026-43895jq: Embedded NUL in jq import paths causes local redaction-policy bypass and preserves sensitive fields in published artifacts | Exploitation statusPublic exploit | FixNot confirmed | Published05/11/2026 | SeverityMedium |
CVE-2026-44777jq: stack overflow in module loading on mutual `include` | Exploitation statusPublic exploit | FixNot confirmed | Published05/11/2026 | SeverityMedium |
CVE-2026-43894jq: Wild stack write via signed-integer overflow in decNumber D2U() macro | Exploitation statusPublic exploit | FixNot confirmed | Published05/11/2026 | SeverityMedium |
CVE-2026-41256jq: Embedded NUL truncates top-level jq programs loaded with -f | Exploitation statusPublic exploit | FixNot confirmed | Published05/11/2026 | SeverityMedium |
CVE-2026-40612jq: Stack overflow via unbounded recursion in jv_contains | Exploitation statusPublic exploit | FixNot confirmed | Published05/11/2026 | SeverityMedium |
CVE-2026-41257jq: Signed-int overflow in `stack_reallocate` (jq VM stack) | Exploitation statusNot known exploited | FixNot confirmed | Published05/11/2026 | SeverityMedium |
CVE-2026-33948jq: Embedded-NUL Truncation in CLI JSON Input Path Causes Prefix-Only Validation of Malformed Input | Exploitation statusPublic exploit | FixYes | Published04/13/2026 | SeverityLow |
CVE-2026-40164jq: Algorithmic complexity DoS via hardcoded MurmurHash3 seed | Exploitation statusPublic exploit | FixYes | Published04/13/2026 | SeverityHigh |
CVE-2026-39979jq: Out-of-Bounds Read in jv_parse_sized() Error Formatting for Non-NUL-Terminated Counted Buffers | Exploitation statusPublic exploit | FixYes | Published04/13/2026 | SeverityMedium |
CVE-2026-39956jq: Missing runtime type checks for _strindices lead to crash and limited memory disclosure | Exploitation statusPublic exploit | FixYes | Published04/13/2026 | SeverityMedium |
CVE-2026-33947jq: Unbounded Recursion in jv_setpath(), jv_getpath() and delpaths_sorted() | Exploitation statusPublic exploit | FixNot confirmed | Published04/13/2026 | SeverityMedium |
CVE-2026-32316jq: Integer overflow in jvp_string_append() allows Heap-based Buffer Overflow | Exploitation statusPublic exploit | FixNot confirmed | Published04/13/2026 | SeverityHigh |
CVE-2025-9403jqlang jq JSON jq_test.c run_jq_tests assertion | Exploitation statusPublic exploit | FixNot confirmed | Published08/25/2025 | SeverityMedium |
CVE-2025-49014jq heap use after free vulnerability in f_strflocaltime | Exploitation statusPublic exploit | FixYes | Published06/19/2025 | SeverityMedium |
CVE-2025-48060AddressSanitizer: stack-buffer-overflow in jq_fuzz_execute (jv_string_vfmt) | Exploitation statusPublic exploit | FixNot confirmed | Published05/21/2025 | SeverityHigh |
CVE-2024-23337jq has signed integer overflow in jv.c:jvp_array_write | Exploitation statusPublic exploit | FixNot confirmed | Published05/21/2025 | SeverityMedium |
CVE-2024-53427 | Exploitation statusPublic exploit | FixNot confirmed | Published02/26/2025 | SeverityHigh |
CVE-2023-50268jq has stack-based buffer overflow in decNaNs | Exploitation statusNot confirmed | FixNot confirmed | Published12/13/2023 | SeverityMedium |
CVE-2023-50246jq has heap-buffer-overflow vulnerability in the function decToString in decNumber.c | Exploitation statusNot known exploited | FixNot confirmed | Published12/13/2023 | SeverityMedium |
CVE-2023-49355 | Exploitation statusPublic exploit | FixNot confirmed | Published12/11/2023 | SeverityHigh |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan