Integer Overflow and Buffer Overrun Vulnerability in jq Command-Line JSON Processor
CVE-2026-54679

6.9MEDIUM

Key Information:

Vendor

Jqlang

Status
Vendor
CVE Published:
25 June 2026

What is CVE-2026-54679?

The jq command-line JSON processor, prior to version 1.8.2, contains a vulnerability in the jvp_string_append function on 32-bit systems, where an integer overflow can occur. This overflow may lead to a significant buffer overrun, potentially enabling attackers to exploit the software by causing unexpected behavior or executing arbitrary code. This issue has been addressed in version 1.8.2, which is recommended for all users to mitigate risks.

Affected Version(s)

jq < 1.8.2

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.