Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-54679

Опубликовано: 25 июн. 2026
Источник: nvd
CVSS3: 5.5
EPSS Низкий

Описание

jq is a command-line JSON processor. Prior to 1.8.2, on 32bit system, jvp_string_append has a chance of integer/multiple overflowing and then causing a massive buffer overrun. This vulnerability is fixed in 1.8.2.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:jqlang:jq:*:*:*:*:*:*:*:*
Версия до 1.8.2 (исключая)

EPSS

Процентиль: 1%
0.00103
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-190

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 1 месяца назад

jq is a command-line JSON processor. Prior to 1.8.2, on 32bit system, jvp_string_append has a chance of integer/multiple overflowing and then causing a massive buffer overrun. This vulnerability is fixed in 1.8.2.

CVSS3: 5.5
redhat
около 1 месяца назад

jq is a command-line JSON processor. Prior to 1.8.2, on 32bit system, jvp_string_append has a chance of integer/multiple overflowing and then causing a massive buffer overrun. This vulnerability is fixed in 1.8.2.

msrc
около 1 месяца назад

jq: potential integer overflow in jvp_string_append

CVSS3: 5.5
debian
около 1 месяца назад

jq is a command-line JSON processor. Prior to 1.8.2, on 32bit system, ...

suse-cvrf
21 день назад

Security update for jq

EPSS

Процентиль: 1%
0.00103
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-190