Jq
Vendor:
First CVE: Dec 11, 2023 · Active for 2 years
22
Total CVEs
More Total CVEs than 95% of tracked products
7.3
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 24% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Jq over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 11, 2023
2 years ago
Most Recent CVE
Jun 25, 2026
33 days ago
CVE Severity & Scoring
Jq22 CVEs
77%
23%
All CVEs353,173 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local16 (72.7%)
Network6 (27.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low21 (95.5%)
High1 (4.5%)
Unknown0 (0.0%)
User Interaction
None13 (59.1%)
Unknown0 (0.0%)
Required9 (40.9%)
Privileges Required
Low7 (31.8%)
High0 (0.0%)
None15 (68.2%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-32316HIGH jq is a command-line JSON processor. An integer overflow vulnerability exists through version 1.8.1 within the jvp_string_append() and jvp_string_copy_replace_bad functions, where | Apr 13, 2026 | 7.5 | 29 | NO | NO |
CVE-2026-39979MEDIUM jq is a command-line JSON processor. In commits before 2f09060afab23fe9390cce7cb860b10416e1bf5f, the jv_parse_sized() API in libjq accepts a counted buffer with an explicit length | Apr 13, 2026 | 6.5 | 28 | NO | NO |
CVE-2026-49839HIGH jq is a command-line JSON processor. Prior to 1.8.2,` jq --rawfile` can turn a handled oversized-string error into invalid-state reuse and a real heap out-of-bounds write in assert | Jun 25, 2026 | 7.1 | 27 | NO | NO |
CVE-2026-47770MEDIUM jq is a command-line JSON processor. Prior to 1.8.2, comparing two sufficiently deeply nested arrays with the == operator exhausts the C stack on jq's ordinary command-line surface | Jun 25, 2026 | 5.5 | 24 | NO | NO |
CVE-2026-54679MEDIUM jq is a command-line JSON processor. Prior to 1.8.2, on 32bit system, jvp_string_append has a chance of integer/multiple overflowing and then causing a massive buffer overrun. Thi | Jun 25, 2026 | 5.5 | 24 | NO | NO |
CVE-2026-44777MEDIUM jq is a command-line JSON processor. In 1.8.2rc1 and earlier, the ordinary module loader recurses without cycle detection when two
otherwise valid modules include each other. | May 11, 2026 | 5.5 | 24 | NO | NO |
CVE-2026-43896MEDIUM jq is a command-line JSON processor. In 1.8.1 and earlier, unbounded recursion in jv_object_merge_recursive() allows a crafted jq program to crash the process with a segfault. The | May 11, 2026 | 5.5 | 24 | NO | NO |
CVE-2026-43894MEDIUM jq is a command-line JSON processor. In 1.8.1 and earlier, when decNumberFromString is given a number literal of INT_MAX-1 (2147483646) digits, the D2U() macro overflows during sig | May 11, 2026 | 5.5 | 24 | NO | NO |
CVE-2026-41257MEDIUM jq is a command-line JSON processor. In 1.8.1 and earlier, the jq bytecode VM's data stack tracks its allocation size in a signed int. When the stack grows beyond ≈1 GiB (via deepl | May 11, 2026 | 5.5 | 24 | NO | NO |
CVE-2026-41256MEDIUM jq is a command-line JSON processor. In 1.8.1 and earlier, Top-level jq programs loaded from a file with -f are truncated at the first embedded NUL byte on current upstream HEAD. A | May 11, 2026 | 5.5 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (22 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (22 CVEs).
Media Mentions
Signals from CVEs in this product scope (22 CVEs).
Top CNAs Publishing CVEs For Jq
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.7-37-g88f01a7 | 1 | 7.5 | 1.2% | 0 | 0 |
| 1.7 | 2 | 5.5 | 0.5% | 0 | 0 |