Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 19

Количество 19

ubuntu логотип

CVE-2026-39979

4 месяца назад

jq is a command-line JSON processor. In commits before 2f09060afab23fe9390cce7cb860b10416e1bf5f, the jv_parse_sized() API in libjq accepts a counted buffer with an explicit length parameter, but its error-handling path formats the input buffer using %s in jv_string_fmt(), which reads until a NUL terminator is found rather than respecting the caller-supplied length. This means that when malformed JSON is passed in a non-NUL-terminated buffer, the error construction logic performs an out-of-bounds read past the end of the buffer. The vulnerability is reachable by any libjq consumer calling jv_parse_sized() with untrusted input, and depending on memory layout, can result in memory disclosure or process termination. The issue has been patched in commit 2f09060afab23fe9390cce7cb860b10416e1bf5f.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2026-39979

4 месяца назад

jq is a command-line JSON processor. In commits before 2f09060afab23fe9390cce7cb860b10416e1bf5f, the jv_parse_sized() API in libjq accepts a counted buffer with an explicit length parameter, but its error-handling path formats the input buffer using %s in jv_string_fmt(), which reads until a NUL terminator is found rather than respecting the caller-supplied length. This means that when malformed JSON is passed in a non-NUL-terminated buffer, the error construction logic performs an out-of-bounds read past the end of the buffer. The vulnerability is reachable by any libjq consumer calling jv_parse_sized() with untrusted input, and depending on memory layout, can result in memory disclosure or process termination. The issue has been patched in commit 2f09060afab23fe9390cce7cb860b10416e1bf5f.

CVSS3: 8.2
EPSS: Низкий
nvd логотип

CVE-2026-39979

4 месяца назад

jq is a command-line JSON processor. In commits before 2f09060afab23fe9390cce7cb860b10416e1bf5f, the jv_parse_sized() API in libjq accepts a counted buffer with an explicit length parameter, but its error-handling path formats the input buffer using %s in jv_string_fmt(), which reads until a NUL terminator is found rather than respecting the caller-supplied length. This means that when malformed JSON is passed in a non-NUL-terminated buffer, the error construction logic performs an out-of-bounds read past the end of the buffer. The vulnerability is reachable by any libjq consumer calling jv_parse_sized() with untrusted input, and depending on memory layout, can result in memory disclosure or process termination. The issue has been patched in commit 2f09060afab23fe9390cce7cb860b10416e1bf5f.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2026-39979

4 месяца назад

jq: Out-of-Bounds Read in jv_parse_sized() Error Formatting for Non-NUL-Terminated Counted Buffers

EPSS: Низкий
debian логотип

CVE-2026-39979

4 месяца назад

jq is a command-line JSON processor. In commits before 2f09060afab23fe ...

CVSS3: 6.5
EPSS: Низкий
fstec логотип

BDU:2026-05572

4 месяца назад

Уязвимость функции jv_parse_sized() функционального языка программирования jq, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 9.1
EPSS: Низкий
redos логотип

ROS-20260708-73-0052

25 дней назад

Уязвимость jq

CVSS3: 9.1
EPSS: Низкий
rocky логотип

RLSA-2026:19365

2 месяца назад

Important: jq security update

EPSS: Низкий
rocky логотип

RLSA-2026:19151

2 месяца назад

Important: jq security update

EPSS: Низкий
rocky логотип

RLSA-2026:16693

3 месяца назад

Important: jq security update

EPSS: Низкий
rocky логотип

RLSA-2026:16692

3 месяца назад

Important: jq security update

EPSS: Низкий
rocky логотип

RLSA-2026:16252

3 месяца назад

Important: jq security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-19365

около 1 месяца назад

ELSA-2026-19365: jq security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-19151

17 дней назад

ELSA-2026-19151: jq security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-16693

3 месяца назад

ELSA-2026-16693: jq security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-16692

3 месяца назад

ELSA-2026-16692: jq security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-16252

3 месяца назад

ELSA-2026-16252: jq security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2983-1

18 дней назад

Security update for jq

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21248-1

25 дней назад

Security update for jq

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-39979

jq is a command-line JSON processor. In commits before 2f09060afab23fe9390cce7cb860b10416e1bf5f, the jv_parse_sized() API in libjq accepts a counted buffer with an explicit length parameter, but its error-handling path formats the input buffer using %s in jv_string_fmt(), which reads until a NUL terminator is found rather than respecting the caller-supplied length. This means that when malformed JSON is passed in a non-NUL-terminated buffer, the error construction logic performs an out-of-bounds read past the end of the buffer. The vulnerability is reachable by any libjq consumer calling jv_parse_sized() with untrusted input, and depending on memory layout, can result in memory disclosure or process termination. The issue has been patched in commit 2f09060afab23fe9390cce7cb860b10416e1bf5f.

CVSS3: 6.5
1%
Низкий
4 месяца назад
redhat логотип
CVE-2026-39979

jq is a command-line JSON processor. In commits before 2f09060afab23fe9390cce7cb860b10416e1bf5f, the jv_parse_sized() API in libjq accepts a counted buffer with an explicit length parameter, but its error-handling path formats the input buffer using %s in jv_string_fmt(), which reads until a NUL terminator is found rather than respecting the caller-supplied length. This means that when malformed JSON is passed in a non-NUL-terminated buffer, the error construction logic performs an out-of-bounds read past the end of the buffer. The vulnerability is reachable by any libjq consumer calling jv_parse_sized() with untrusted input, and depending on memory layout, can result in memory disclosure or process termination. The issue has been patched in commit 2f09060afab23fe9390cce7cb860b10416e1bf5f.

CVSS3: 8.2
1%
Низкий
4 месяца назад
nvd логотип
CVE-2026-39979

jq is a command-line JSON processor. In commits before 2f09060afab23fe9390cce7cb860b10416e1bf5f, the jv_parse_sized() API in libjq accepts a counted buffer with an explicit length parameter, but its error-handling path formats the input buffer using %s in jv_string_fmt(), which reads until a NUL terminator is found rather than respecting the caller-supplied length. This means that when malformed JSON is passed in a non-NUL-terminated buffer, the error construction logic performs an out-of-bounds read past the end of the buffer. The vulnerability is reachable by any libjq consumer calling jv_parse_sized() with untrusted input, and depending on memory layout, can result in memory disclosure or process termination. The issue has been patched in commit 2f09060afab23fe9390cce7cb860b10416e1bf5f.

CVSS3: 6.5
1%
Низкий
4 месяца назад
msrc логотип
CVE-2026-39979

jq: Out-of-Bounds Read in jv_parse_sized() Error Formatting for Non-NUL-Terminated Counted Buffers

1%
Низкий
4 месяца назад
debian логотип
CVE-2026-39979

jq is a command-line JSON processor. In commits before 2f09060afab23fe ...

CVSS3: 6.5
1%
Низкий
4 месяца назад
fstec логотип
BDU:2026-05572

Уязвимость функции jv_parse_sized() функционального языка программирования jq, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 9.1
1%
Низкий
4 месяца назад
redos логотип
ROS-20260708-73-0052

Уязвимость jq

CVSS3: 9.1
1%
Низкий
25 дней назад
rocky логотип
RLSA-2026:19365

Important: jq security update

2 месяца назад
rocky логотип
RLSA-2026:19151

Important: jq security update

2 месяца назад
rocky логотип
RLSA-2026:16693

Important: jq security update

3 месяца назад
rocky логотип
RLSA-2026:16692

Important: jq security update

3 месяца назад
rocky логотип
RLSA-2026:16252

Important: jq security update

3 месяца назад
oracle-oval логотип
ELSA-2026-19365

ELSA-2026-19365: jq security update (IMPORTANT)

около 1 месяца назад
oracle-oval логотип
ELSA-2026-19151

ELSA-2026-19151: jq security update (IMPORTANT)

17 дней назад
oracle-oval логотип
ELSA-2026-16693

ELSA-2026-16693: jq security update (IMPORTANT)

3 месяца назад
oracle-oval логотип
ELSA-2026-16692

ELSA-2026-16692: jq security update (IMPORTANT)

3 месяца назад
oracle-oval логотип
ELSA-2026-16252

ELSA-2026-16252: jq security update (IMPORTANT)

3 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2983-1

Security update for jq

18 дней назад
suse-cvrf логотип
openSUSE-SU-2026:21248-1

Security update for jq

25 дней назад

Уязвимостей на страницу