PT-2026-47092 · Jq · Jq

·

CVE-2026-47770

·

Published

2026-05-08

·

Updated

2026-07-06

CVSS v4.0

6.8

Medium

VectorAV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions jq versions prior to 1.8.2
Description Comparing two deeply nested arrays using the == operator can lead to a denial of service through stack exhaustion caused by uncontrolled recursion. The issue occurs within the recursive structural comparison code, specifically involving the jvp array equal() and jv equal() functions in src/jv.c. Additionally, a sort comparator path through the jv cmp() function in src/jv aux.c can also cause a stack overflow at a greater nesting depth due to a missing recursion guard. This affects users who perform comparisons on attacker-controlled deeply nested JSON values or embed the software in environments where untrusted data reaches the == comparison path.
Recommendations Update to version 1.8.2.

Exploit

Fix

DoS

Uncontrolled Recursion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-90273
BDU:2026-12864
CVE-2026-47770
ECHO-B834-A843-3668
GHSA-3PGX-FRR7-3JXP
OESA-2026-2803
OESA-2026-2804
OESA-2026-2805
OESA-2026-2806
OPENSUSE-SU-2026:11133-1

Affected Products

Jq