Heap Buffer Overflow in jq Command-Line JSON Processor
CVE-2025-48060

7.7HIGH

Key Information:

Vendor

Jqlang

Status
Vendor
CVE Published:
21 May 2025

What is CVE-2025-48060?

A heap-buffer-overflow vulnerability exists in the jq command-line JSON processor due to improper memory handling in the jv_string_vfmt function. This issue, found in the jq_fuzz_execute harness, could potentially allow attackers to execute arbitrary code or crash the application. No patched versions are currently available, making users of jq versions up to and including 1.7.1 susceptible. It is recommended to take precautions while using affected versions.

Affected Version(s)

jq <= 1.7.1

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-48060 : Heap Buffer Overflow in jq Command-Line JSON Processor