CVE-2026-54679

jq is a command-line JSON processor. Prior to 1.8.2, on 32bit system, jvp_string_append has a chance of integer/multiple overflowing and then causing a massive buffer overrun. This vulnerability is fixed in 1.8.2.
Configurations

Configuration 1 (hide)

cpe:2.3:a:jqlang:jq:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-06-25 18:16

Updated : 2026-06-26 18:53


NVD link : CVE-2026-54679

Mitre link : CVE-2026-54679

CVE.ORG link : CVE-2026-54679


JSON object : View

Products Affected

jqlang

  • jq
CWE
CWE-190

Integer Overflow or Wraparound