Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-43896

Опубликовано: 11 мая 2026
Источник: redhat
CVSS3: 5.5

Описание

jq is a command-line JSON processor. In 1.8.1 and earlier, unbounded recursion in jv_object_merge_recursive() allows a crafted jq program to crash the process with a segfault. The function is reachable through the * operator when both operands are objects.

A flaw was found in jq, a command line JSON processor. The jv_object_merge_recursive function, reachable via the * operator when both operands are objects, does not have a depth limit when processing nested objects. This missing depth limit allows an attacker who can supply a sufficiently nested input structure to exhaust the stack memory, causing an application crash and resulting in a denial of service.

Отчет

To exploit this issue, an attacker needs to supply a crafted JSON input to be processed by jq with the jv_object_merge_recursive function, reachable via the * operator when both operands are objects. This allows the attacker to cause an application crash with no other security impact. Due to these reasons, this vulnerability has been rated with a moderate severity.

Меры по смягчению последствий

Do not process untrusted input with the jq command line JSON processor.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/controller-rhel9Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/hub-rhel9Fix deferred
Red Hat Ansible Automation Platform 2automation-controllerFix deferred
Red Hat Ceph Storage 4jqFix deferred
Red Hat Enterprise Linux 10jqOut of support scope
Red Hat Enterprise Linux 8jqFix deferred
Red Hat Enterprise Linux 9jqFix deferred
Red Hat OpenShift Container Platform 4rhcosFix deferred
Red Hat Hardened Imagesjq-main-1.8.2-0.1.hum1FixedRHSA-2026:2998625.06.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-674
https://bugzilla.redhat.com/show_bug.cgi?id=2469184jq: stack overflow in recursive object merge

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.2
ubuntu
3 месяца назад

jq is a command-line JSON processor. In 1.8.1 and earlier, unbounded recursion in jv_object_merge_recursive() allows a crafted jq program to crash the process with a segfault. The function is reachable through the * operator when both operands are objects.

CVSS3: 6.2
nvd
3 месяца назад

jq is a command-line JSON processor. In 1.8.1 and earlier, unbounded recursion in jv_object_merge_recursive() allows a crafted jq program to crash the process with a segfault. The function is reachable through the * operator when both operands are objects.

CVSS3: 6.2
msrc
3 месяца назад

jq: Stack Overflow in Recursive Object Merge

CVSS3: 6.2
debian
3 месяца назад

jq is a command-line JSON processor. In 1.8.1 and earlier, unbounded r ...

CVSS3: 5.5
fstec
3 месяца назад

Уязвимость функции jv_object_merge_recursive() утилиты для обработки JSON-файлов jq, позволяющая нарушителю вызвать отказ в обслуживании

5.5 Medium

CVSS3