Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-39979

28
FAUCET Score

VULNERABILITY OVERVIEW CVE-2026-39979 affects jq, a widely-used command-line JSON processor, and specifically impacts the jv_parse_sized() API in the libjq library. The vulnerability stems from a buffer handling flaw where error-handling code fails to respect an explicitly-provided buffer length parameter, instead reading until a NUL terminator is found. This creates an out-of-bounds read condition when malformed JSON is passed in non-NUL-terminated buffers. SEVERITY ASSESSMENT The vulnerability is reachable through any libjq consumer that calls jv_parse_sized() with untrusted input, making the attack vector straightforward for applications integrating this library. The flaw can result in memory disclosure or process termination depending on memory layout, though the CVSS score is not yet published. With an EPSS score of 0.00055 and FAUCET Risk Score of 46.0/100, the vulnerability presents moderate concern within the broader threat landscape. EXPLOITATION STATUS There is no evidence of active exploitation, and the vulnerability is not tracked on the Known Exploited Vulnerabilities (KEV) catalog. The issue has been patched in commit 2f09060afab23fe9390cce7cb860b10416e1bf5f, and organizations should prioritize updating to patched versions of jq and any dependent applications. Community attention appears minimal at this stage, with the vulnerability remaining on the inactive Hot List.

Impacted Technologies

VendorProductVersion(s)CPE
< 2026-04-12CPE matchmatch criteria
cpe:2.3:a:jqlang:jq:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

6.9MEDIUM

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
LOW
VS Integrity
NONE
VS Availability
LOW
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.56%
Probability of exploitation in next 30 days
EPSS Percentile
43.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0056 is in the 27th percentile among its peer group of 23,723 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

microsoftpatch availablevia msrc
Product: 20607-17086Fixed in: 1.6-6
microsoftpatch availablevia msrc
Product: cbl2 jq 1.6-5 on CBL Mariner 2.0Fixed in: 1.6-6
microsoftpatch availablevia msrc
Product: azl3 jq 1.7.1-4 on Azure Linux 3.0Fixed in: 1.7.1-5
microsoftpatch availablevia msrc
Product: 19612-17084Fixed in: 1.7.1-5

Vendor Advisories (1)

microsoft2026-Apr/CVE-2026-39979Moderate

jq: Out-of-Bounds Read in jv_parse_sized() Error Formatting for Non-NUL-Terminated Counted Buffers

Apr 14, 2026

References

access.redhat.com / errata/RHSA-2026:16252
access.redhat.com / errata/RHSA-2026:16692
access.redhat.com / errata/RHSA-2026:16693
access.redhat.com / errata/RHSA-2026:18040
access.redhat.com / errata/RHSA-2026:18042
access.redhat.com / errata/RHSA-2026:18043
access.redhat.com / errata/RHSA-2026:18044
access.redhat.com / errata/RHSA-2026:18045
access.redhat.com / errata/RHSA-2026:18046
access.redhat.com / errata/RHSA-2026:18047
access.redhat.com / errata/RHSA-2026:18048
access.redhat.com / errata/RHSA-2026:19151
access.redhat.com / errata/RHSA-2026:19365
access.redhat.com / errata/RHSA-2026:23233
access.redhat.com / errata/RHSA-2026:23245
access.redhat.com / errata/RHSA-2026:25044
access.redhat.com / errata/RHSA-2026:25096
access.redhat.com / errata/RHSA-2026:25181
access.redhat.com / errata/RHSA-2026:26528
access.redhat.com / errata/RHSA-2026:26542
access.redhat.com / errata/RHSA-2026:28887
access.redhat.com / errata/RHSA-2026:30078
access.redhat.com / errata/RHSA-2026:30087
access.redhat.com / errata/RHSA-2026:30088
access.redhat.com / errata/RHSA-2026:30089
access.redhat.com / errata/RHSA-2026:34098
access.redhat.com / errata/RHSA-2026:8579
access.redhat.com / security/cve/CVE-2026-39979
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-39979.json
github.com / jqlang/jq/commit/2f09060afab23fe9390cce7cb860b10416e1bf5f
Patch
github.com / jqlang/jq/security/advisories/GHSA-2hhh-px8h-355p
ExploitVendor Advisory