← Vulnerability feed

Vulnerability record · CVE-2026-39979 · published 13 April 2026

CVE-2026-39979: Jqlang jq out-of-bounds read vulnerability

Jqlang · Jq

jq is a command-line JSON processor. In commits before 2f09060afab23fe9390cce7cb860b10416e1bf5f, the jv_parse_sized() API in libjq accepts a counted buffer with an explicit length parameter, but its error-handling path formats the input buffer using %s in jv_string_fmt(), which reads until a NUL terminator is found rather than respecting the caller-supplied length. This means that when malformed JSON is passed in a non-NUL-terminated buffer, the error construction logic performs an out-of-bounds read past the end of the buffer. The vulnerability is reachable by any libjq consumer calling jv_parse_sized() with untrusted input, and depending on memory layout, can result in memory disclosure or process termination. The issue has been patched in commit 2f09060afab23fe9390cce7cb860b10416e1bf5f.

6.9 CVSS 4.0 Medium EPSS 0.82% · top 44.3% CWE-125 · Out-of-bounds read
6.9CVSS 4.0 base score
0.82%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
33References, 2 tagged exploit
15 Jul 2026Last modified by NVD

Description

jq is a command-line JSON processor. In commits before 2f09060afab23fe9390cce7cb860b10416e1bf5f, the jv_parse_sized() API in libjq accepts a counted buffer with an explicit length parameter, but its error-handling path formats the input buffer using %s in jv_string_fmt(), which reads until a NUL terminator is found rather than respecting the caller-supplied length. This means that when malformed JSON is passed in a non-NUL-terminated buffer, the error construction logic performs an out-of-bounds read past the end of the buffer. The vulnerability is reachable by any libjq consumer calling jv_parse_sized() with untrusted input, and depending on memory layout, can result in memory disclosure or process termination. The issue has been patched in commit 2f09060afab23fe9390cce7cb860b10416e1bf5f.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/jqlang/jq/commit/2f09060afab23fe9390cce7cb860b10416e1bf5f Patch
https://github.com/jqlang/jq/security/advisories/GHSA-2hhh-px8h-355p ExploitVendor Advisory
https://access.redhat.com/errata/RHSA-2026:16252
https://access.redhat.com/errata/RHSA-2026:16692
https://access.redhat.com/errata/RHSA-2026:16693
https://access.redhat.com/errata/RHSA-2026:18040
https://access.redhat.com/errata/RHSA-2026:18042
https://access.redhat.com/errata/RHSA-2026:18043
https://access.redhat.com/errata/RHSA-2026:18044
https://access.redhat.com/errata/RHSA-2026:18045
https://access.redhat.com/errata/RHSA-2026:18046
https://access.redhat.com/errata/RHSA-2026:18047
https://access.redhat.com/errata/RHSA-2026:18048
https://access.redhat.com/errata/RHSA-2026:19151
https://access.redhat.com/errata/RHSA-2026:19365
https://access.redhat.com/errata/RHSA-2026:23233
https://access.redhat.com/errata/RHSA-2026:23245
https://access.redhat.com/errata/RHSA-2026:25044
https://access.redhat.com/errata/RHSA-2026:25096
https://access.redhat.com/errata/RHSA-2026:25181
https://access.redhat.com/errata/RHSA-2026:26528
https://access.redhat.com/errata/RHSA-2026:26542
https://access.redhat.com/errata/RHSA-2026:28887
https://access.redhat.com/errata/RHSA-2026:30078
https://access.redhat.com/errata/RHSA-2026:30087
https://access.redhat.com/errata/RHSA-2026:30088
https://access.redhat.com/errata/RHSA-2026:30089
https://access.redhat.com/errata/RHSA-2026:34098
https://access.redhat.com/errata/RHSA-2026:8579
https://access.redhat.com/security/cve/CVE-2026-39979
https://bugzilla.redhat.com/show_bug.cgi?id=2458077
https://github.com/jqlang/jq/security/advisories/GHSA-2hhh-px8h-355p ExploitVendor Advisory
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39979.json

Track CVE-2026-39979 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.1CVE-2024-53427Jqlang jq type confusion vulnerabilitydecNumberCopy in decNumber.c in jq through 1.7.1 does not properly consider that NaN is interpreted as numeric, which has a resultant stack-based buf…EPSS 0.36%7.7CVE-2025-48060Jqlang jq stack-based buffer overflow vulnerabilityjq is a command-line JSON processor. In versions up to and including 1.7.1, a heap-buffer-overflow is present in function `jv_string_vfmt` in the jq_…EPSS 0.53%7.5CVE-2026-32316Jqlang jq heap-based buffer overflow vulnerabilityjq is a command-line JSON processor. An integer overflow vulnerability exists through version 1.8.1 within the jvp_string_append() and jvp_string_cop…EPSS 0.49%7.5CVE-2023-49355Jqlang jq out-of-bounds write vulnerabilitydecToString in decNumber/decNumber.c in jq 88f01a7 has a one-byte out-of-bounds write via the " []-1.2e-1111111111" input. NOTE: this is not the same…EPSS 1.2%7.1CVE-2026-49839Jqlang jq out-of-bounds write vulnerabilityjq is a command-line JSON processor. Prior to 1.8.2,` jq --rawfile` can turn a handled oversized-string error into invalid-state reuse and a real hea…EPSS 0.17%6.9CVE-2026-54679Jqlang jq integer overflow vulnerabilityjq is a command-line JSON processor. Prior to 1.8.2, on 32bit system, jvp_string_append has a chance of integer/multiple overflowing and then causing…EPSS 0.15%6.8CVE-2026-47770Jqlang jq vulnerabilityjq is a command-line JSON processor. Prior to 1.8.2, comparing two sufficiently deeply nested arrays with the == operator exhausts the C stack on jq'…EPSS 0.16%6.5CVE-2024-23337Jqlang jq integer overflow vulnerabilityjq is a command-line JSON processor. In versions up to and including 1.7.1, an integer overflow arises when assigning value using an index of 2147483…EPSS 0.44%

Source: NIST National Vulnerability Database (record CVE-2026-39979), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.