PT-2026-52519 · Jq · Jq

·

CVE-2026-54679

·

Published

2026-06-25

·

Updated

2026-07-22

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions jq versions prior to 1.8.2
Description On 32-bit systems, the jvp string append() function is susceptible to integer or multiplication overflow, which can lead to a significant buffer overrun. A buffer overrun occurs when a program writes more data to a block of memory than it is allocated to hold, potentially corrupting adjacent memory.
Recommendations Update to version 1.8.2.

Exploit

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54679
ECHO-DFA5-57C7-BA16
GHSA-29GJ-222P-J7VX
OESA-2026-2803
OESA-2026-2804
OESA-2026-2805
OESA-2026-2806
OPENSUSE-SU-2026:11133-1
OPENSUSE-SU-2026:21318-1
SUSE-SU-2026:22597-1
SUSE-SU-2026:22637-1
SUSE-SU-2026:22900-1

Affected Products

Jq