Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 9

Количество 9

fstec логотип

BDU:2026-05501

4 месяца назад

Уязвимость функций jv_setpath(), jv_getpath(), delpaths_sorted() функционального языка программирования jq, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 6.2
EPSS: Низкий
redos логотип

ROS-20260708-73-0051

около 1 месяца назад

Уязвимость jq

CVSS3: 6.2
EPSS: Низкий
ubuntu логотип

CVE-2026-33947

4 месяца назад

jq is a command-line JSON processor. In versions 1.8.1 and below, functions jv_setpath(), jv_getpath(), and delpaths_sorted() in jq's src/jv_aux.c use unbounded recursion whose depth is controlled by the length of a caller-supplied path array, with no depth limit enforced. An attacker can supply a JSON document containing a flat array of ~65,000 integers (~200 KB) that, when used as a path argument by a trusted jq filter, exhausts the C call stack and crashes the process with a segmentation fault (SIGSEGV). This bypass works because the existing MAX_PARSING_DEPTH (10,000) limit only protects the JSON parser, not runtime path operations where arrays can be programmatically constructed to arbitrary lengths. The impact is denial of service (unrecoverable crash) affecting any application or service that processes untrusted JSON input through jq's setpath, getpath, or delpaths builtins. This issue has been addressed in commit fb59f1491058d58bdc3e8dd28f1773d1ac690a1f.

CVSS3: 6.2
EPSS: Низкий
redhat логотип

CVE-2026-33947

4 месяца назад

jq is a command-line JSON processor. In versions 1.8.1 and below, functions jv_setpath(), jv_getpath(), and delpaths_sorted() in jq's src/jv_aux.c use unbounded recursion whose depth is controlled by the length of a caller-supplied path array, with no depth limit enforced. An attacker can supply a JSON document containing a flat array of ~65,000 integers (~200 KB) that, when used as a path argument by a trusted jq filter, exhausts the C call stack and crashes the process with a segmentation fault (SIGSEGV). This bypass works because the existing MAX_PARSING_DEPTH (10,000) limit only protects the JSON parser, not runtime path operations where arrays can be programmatically constructed to arbitrary lengths. The impact is denial of service (unrecoverable crash) affecting any application or service that processes untrusted JSON input through jq's setpath, getpath, or delpaths builtins. This issue has been addressed in commit fb59f1491058d58bdc3e8dd28f1773d1ac690a1f.

CVSS3: 6.2
EPSS: Низкий
nvd логотип

CVE-2026-33947

4 месяца назад

jq is a command-line JSON processor. In versions 1.8.1 and below, functions jv_setpath(), jv_getpath(), and delpaths_sorted() in jq's src/jv_aux.c use unbounded recursion whose depth is controlled by the length of a caller-supplied path array, with no depth limit enforced. An attacker can supply a JSON document containing a flat array of ~65,000 integers (~200 KB) that, when used as a path argument by a trusted jq filter, exhausts the C call stack and crashes the process with a segmentation fault (SIGSEGV). This bypass works because the existing MAX_PARSING_DEPTH (10,000) limit only protects the JSON parser, not runtime path operations where arrays can be programmatically constructed to arbitrary lengths. The impact is denial of service (unrecoverable crash) affecting any application or service that processes untrusted JSON input through jq's setpath, getpath, or delpaths builtins. This issue has been addressed in commit fb59f1491058d58bdc3e8dd28f1773d1ac690a1f.

CVSS3: 6.2
EPSS: Низкий
msrc логотип

CVE-2026-33947

4 месяца назад

jq: Unbounded Recursion in jv_setpath(), jv_getpath() and delpaths_sorted()

CVSS3: 6.2
EPSS: Низкий
debian логотип

CVE-2026-33947

4 месяца назад

jq is a command-line JSON processor. In versions 1.8.1 and below, func ...

CVSS3: 6.2
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2983-1

24 дня назад

Security update for jq

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21248-1

около 1 месяца назад

Security update for jq

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2026-05501

Уязвимость функций jv_setpath(), jv_getpath(), delpaths_sorted() функционального языка программирования jq, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 6.2
0%
Низкий
4 месяца назад
redos логотип
ROS-20260708-73-0051

Уязвимость jq

CVSS3: 6.2
0%
Низкий
около 1 месяца назад
ubuntu логотип
CVE-2026-33947

jq is a command-line JSON processor. In versions 1.8.1 and below, functions jv_setpath(), jv_getpath(), and delpaths_sorted() in jq's src/jv_aux.c use unbounded recursion whose depth is controlled by the length of a caller-supplied path array, with no depth limit enforced. An attacker can supply a JSON document containing a flat array of ~65,000 integers (~200 KB) that, when used as a path argument by a trusted jq filter, exhausts the C call stack and crashes the process with a segmentation fault (SIGSEGV). This bypass works because the existing MAX_PARSING_DEPTH (10,000) limit only protects the JSON parser, not runtime path operations where arrays can be programmatically constructed to arbitrary lengths. The impact is denial of service (unrecoverable crash) affecting any application or service that processes untrusted JSON input through jq's setpath, getpath, or delpaths builtins. This issue has been addressed in commit fb59f1491058d58bdc3e8dd28f1773d1ac690a1f.

CVSS3: 6.2
0%
Низкий
4 месяца назад
redhat логотип
CVE-2026-33947

jq is a command-line JSON processor. In versions 1.8.1 and below, functions jv_setpath(), jv_getpath(), and delpaths_sorted() in jq's src/jv_aux.c use unbounded recursion whose depth is controlled by the length of a caller-supplied path array, with no depth limit enforced. An attacker can supply a JSON document containing a flat array of ~65,000 integers (~200 KB) that, when used as a path argument by a trusted jq filter, exhausts the C call stack and crashes the process with a segmentation fault (SIGSEGV). This bypass works because the existing MAX_PARSING_DEPTH (10,000) limit only protects the JSON parser, not runtime path operations where arrays can be programmatically constructed to arbitrary lengths. The impact is denial of service (unrecoverable crash) affecting any application or service that processes untrusted JSON input through jq's setpath, getpath, or delpaths builtins. This issue has been addressed in commit fb59f1491058d58bdc3e8dd28f1773d1ac690a1f.

CVSS3: 6.2
0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-33947

jq is a command-line JSON processor. In versions 1.8.1 and below, functions jv_setpath(), jv_getpath(), and delpaths_sorted() in jq's src/jv_aux.c use unbounded recursion whose depth is controlled by the length of a caller-supplied path array, with no depth limit enforced. An attacker can supply a JSON document containing a flat array of ~65,000 integers (~200 KB) that, when used as a path argument by a trusted jq filter, exhausts the C call stack and crashes the process with a segmentation fault (SIGSEGV). This bypass works because the existing MAX_PARSING_DEPTH (10,000) limit only protects the JSON parser, not runtime path operations where arrays can be programmatically constructed to arbitrary lengths. The impact is denial of service (unrecoverable crash) affecting any application or service that processes untrusted JSON input through jq's setpath, getpath, or delpaths builtins. This issue has been addressed in commit fb59f1491058d58bdc3e8dd28f1773d1ac690a1f.

CVSS3: 6.2
0%
Низкий
4 месяца назад
msrc логотип
CVE-2026-33947

jq: Unbounded Recursion in jv_setpath(), jv_getpath() and delpaths_sorted()

CVSS3: 6.2
0%
Низкий
4 месяца назад
debian логотип
CVE-2026-33947

jq is a command-line JSON processor. In versions 1.8.1 and below, func ...

CVSS3: 6.2
0%
Низкий
4 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2983-1

Security update for jq

24 дня назад
suse-cvrf логотип
openSUSE-SU-2026:21248-1

Security update for jq

около 1 месяца назад

Уязвимостей на страницу

exploitDog - Комплексное решение для обнаружения, оценки и устранения уязвимостей.