CVE-2026-32316

EUVD-2026-22039
jq is a command-line JSON processor. An integer overflow vulnerability exists through version 1.8.1 within the jvp_string_append() and jvp_string_copy_replace_bad functions, where concatenating strings with a combined length exceeding 2^31 bytes causes a 32-bit unsigned integer overflow in the buffer allocation size calculation, resulting in a drastically undersized heap buffer. Subsequent memory copy operations then write the full string data into this undersized buffer, causing a heap buffer overflow classified as CWE-190 (Integer Overflow) leading to CWE-122 (Heap-based Buffer Overflow). Any system evaluating untrusted jq queries is affected, as an attacker can crash the process or potentially achieve further exploitation through heap corruption by crafting queries that produce extremely large strings. The root cause is the absence of string size bounds checking, unlike arrays and objects which already have size limits. The issue has been addressed in commit e47e56d226519635768e6aab2f38f0ab037c09e5.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.2 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 39.51%
Affected Products (NVD)
VendorProductVersion
jqlangjq
𝑥
≤ 1.8.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
jq
bookworm
1.6-2.1+deb12u2
fixed
bookworm (security)
1.6-2.1+deb12u2
fixed
bullseye
vulnerable
bullseye (security)
1.6-2.1+deb11u3
fixed
forky
1.8.2-1
fixed
sid
1.8.2-1
fixed
trixie
vulnerable
trixie (security)
1.7.1-6+deb13u3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
jq
bionic
Fixed 1.5+dfsg-2ubuntu0.1~esm2
released
focal
Fixed 1.6-1ubuntu0.20.04.1+esm2
released
jammy
Fixed 1.6-2.1ubuntu3.2
released
noble
Fixed 1.7.1-3ubuntu0.24.04.2
released
questing
Fixed 1.8.1-3ubuntu1.1
released
resolute
Fixed 1.8.1-4ubuntu2
released
trusty
ignored
xenial
Fixed 1.5+dfsg-1ubuntu0.1+esm4
released
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
jq
suse enterprise desktop 15 SP7
1.6-150000.3.20.1
fixed
suse enterprise sap 15 SP7
1.6-150000.3.20.1
fixed
suse enterprise server 15 SP4
1.6-150000.3.20.1
fixed
suse enterprise server 15 SP7
1.6-150000.3.20.1
fixed
libjq-devel
suse enterprise desktop 15 SP7
1.6-150000.3.20.1
fixed
suse enterprise sap 15 SP7
1.6-150000.3.20.1
fixed
suse enterprise server 15 SP4
1.6-150000.3.20.1
fixed
suse enterprise server 15 SP7
1.6-150000.3.20.1
fixed
libjq1
suse enterprise desktop 15 SP7
1.6-150000.3.20.1
fixed
suse enterprise sap 15 SP7
1.6-150000.3.20.1
fixed
suse enterprise server 15 SP4
1.6-150000.3.20.1
fixed
suse enterprise server 15 SP7
1.6-150000.3.20.1
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
jq
Amazon Linux 2
0:1.6-17.amzn2.0.1
fixed
Amazon Linux 2023
0:1.8.1-59.amzn2023
fixed
jq-debuginfo
Amazon Linux 2
0:1.6-17.amzn2.0.1
fixed
Amazon Linux 2023
0:1.8.1-59.amzn2023
fixed
jq-debugsource
Amazon Linux 2023
0:1.8.1-59.amzn2023
fixed
jq-devel
Amazon Linux 2
0:1.6-17.amzn2.0.1
fixed
Amazon Linux 2023
0:1.8.1-59.amzn2023
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
jq
Azure Linux 3.0
0:1.7.1-5.azl3
fixed