Jq

Vendor:

First CVE: Dec 11, 2023 · Active for 2 years

22
Total CVEs
More Total CVEs than 95% of tracked products
7.3
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 24% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Jq over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 11, 2023
2 years ago
Most Recent CVE
Jun 25, 2026
33 days ago

CVE Severity & Scoring

Jq22 CVEs
All CVEs353,173 CVEs
MediumHigh
Attack Vector
Local16 (72.7%)
Network6 (27.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low21 (95.5%)
High1 (4.5%)
Unknown0 (0.0%)
User Interaction
None13 (59.1%)
Unknown0 (0.0%)
Required9 (40.9%)
Privileges Required
Low7 (31.8%)
High0 (0.0%)
None15 (68.2%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (22 CVEs).

22 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
jq is a command-line JSON processor. An integer overflow vulnerability exists through version 1.8.1 within the jvp_string_append() and jvp_string_copy_replace_bad functions, where
Apr 13, 20267.529NONO
jq is a command-line JSON processor. In commits before 2f09060afab23fe9390cce7cb860b10416e1bf5f, the jv_parse_sized() API in libjq accepts a counted buffer with an explicit length
Apr 13, 20266.528NONO
jq is a command-line JSON processor. Prior to 1.8.2,` jq --rawfile` can turn a handled oversized-string error into invalid-state reuse and a real heap out-of-bounds write in assert
Jun 25, 20267.127NONO
jq is a command-line JSON processor. Prior to 1.8.2, comparing two sufficiently deeply nested arrays with the == operator exhausts the C stack on jq's ordinary command-line surface
Jun 25, 20265.524NONO
jq is a command-line JSON processor. Prior to 1.8.2, on 32bit system, jvp_string_append has a chance of integer/multiple overflowing and then causing a massive buffer overrun. Thi
Jun 25, 20265.524NONO
jq is a command-line JSON processor. In 1.8.2rc1 and earlier, the ordinary module loader recurses without cycle detection when two otherwise valid modules include each other.
May 11, 20265.524NONO
jq is a command-line JSON processor. In 1.8.1 and earlier, unbounded recursion in jv_object_merge_recursive() allows a crafted jq program to crash the process with a segfault. The
May 11, 20265.524NONO
jq is a command-line JSON processor. In 1.8.1 and earlier, when decNumberFromString is given a number literal of INT_MAX-1 (2147483646) digits, the D2U() macro overflows during sig
May 11, 20265.524NONO
jq is a command-line JSON processor. In 1.8.1 and earlier, the jq bytecode VM's data stack tracks its allocation size in a signed int. When the stack grows beyond ≈1 GiB (via deepl
May 11, 20265.524NONO
jq is a command-line JSON processor. In 1.8.1 and earlier, Top-level jq programs loaded from a file with -f are truncated at the first embedded NUL byte on current upstream HEAD. A
May 11, 20265.524NONO

Exploit Exposure

Signals from CVEs in this product scope (22 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (22 CVEs).

Media Mentions

Signals from CVEs in this product scope (22 CVEs).

Top CNAs Publishing CVEs For Jq

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.7-37-g88f01a717.51.2%00
1.725.50.5%00