Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-23337

20
FAUCET Score

CVE-2024-23337 is an integer overflow vulnerability affecting jqlang jq versions up to and including 1.7.1. This flaw occurs when assigning a value using an index of 2147483647, the signed integer limit, leading to a denial of service. The vulnerability has a CVSS score of 6.5 (Medium), indicating it can be exploited remotely with low attack complexity and no privileges, resulting in high availability impact. User interaction is required for successful exploitation. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules or proof-of-concept code. Community discussion and media coverage for this CVE are minimal.

Impacted Technologies

VendorProductVersion(s)CPE
<= 1.7.1CPE matchmatch criteria
cpe:2.3:a:jqlang:jq:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

4.3MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
LOW
Exploitability Score
2.8
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.37%
Probability of exploitation in next 30 days
EPSS Percentile
29.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0037 is in the 30th percentile among its peer group of 26,236 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (24)

github_advisorypatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: cbl2 jq 1.6-3 on CBL Mariner 2.0Fixed in: 1.6-3
microsoftpatch availablevia msrc
Product: 19526-17084Fixed in: 1.7.1-3
microsoftpatch availablevia msrc
Product: 19535-16823Fixed in: 1.6-3
microsoftpatch availablevia msrc
Product: 20292-17086Fixed in: 1.6-3
microsoftpatch availablevia msrc
Product: azl3 jq 1.7.1-3 on Azure Linux 3.0Fixed in: 1.7.1-3
microsoftpatch availablevia msrc
Product: cm2 jq 1.6-3 on CBL Mariner 2.0Fixed in: 1.6-3
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceFixed in: jq-0:1.6-3.el8_6.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsFixed in: jq-0:1.6-3.el8_6.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceFixed in: jq-0:1.6-6.el8_8.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsFixed in: jq-0:1.6-6.el8_8.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: jq-0:1.6-17.el9_6.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsFixed in: jq-0:1.6-12.el9_0.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsFixed in: jq-0:1.6-15.el9_2.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.4 Extended Update SupportFixed in: jq-0:1.6-16.el9_4.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportFixed in: jq-0:1.5-12.el8_4.4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportFixed in: jq-0:1.6-3.el8_6.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-OnFixed in: jq-0:1.6-3.el8_6.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: jq-0:1.7.1-8.el10_0.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: jq-0:1.6-11.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Advanced Update SupportFixed in: jq-0:1.5-12.el8_2.1
View patch
redhatvendor investigatingvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: automation-controller
redhatvendor investigatingvia redhat_api
Product: Red Hat Ceph Storage 4Fixed in: jq
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: rhcos

Vendor Advisories (2)

redhatCVE-2024-23337Moderate

jq: jq has signed integer overflow in jv.c:jvp_array_write

May 21, 2025
microsoft2025-May/CVE-2024-23337Moderate

jq has signed integer overflow in jv.c:jvp_array_write

May 13, 2025

References

github.com / jqlang/jq/commit/de21386681c0df0104a99d9d09db23a9b2a78b1e
Patch
github.com / jqlang/jq/issues/3262
ExploitIssue Tracking
github.com / jqlang/jq/security/advisories/GHSA-2q6r-344g-cx46
ExploitVendor Advisory