Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

jqlang — Vulnerabilities & Security Advisories 23

Browse all 23 CVE security advisories affecting jqlang. AI-powered Chinese analysis, POCs, and references for each vulnerability.

jqlang is a query language primarily used for data extraction and manipulation in JSON structures. Historically, it has been associated with vulnerabilities including remote code execution, cross-site scripting, and privilege escalation, often stemming from improper input validation and insecure deserialization. The project has recorded 13 CVEs, with notable issues including arbitrary code execution through crafted queries and server-side template injection. Security researchers have identified consistent patterns of insufficient sanitization in parsing functions, leading to multiple RCE flaws in versions prior to 2022. While recent versions have addressed some concerns, the language's dynamic nature continues to present potential attack surfaces for complex query-based applications.

Found 23 results / 23 Clear Filters
Top products by jqlang: jq
CVE ID Title CVSS Severity Published
CVE-2026-47770 jq: stack overflow in deep structural equality — jq CWE-674 - - 2026-06-25
CVE-2026-49839 jq --rawfile invalid-state reuse after String too long causes heap-buffer-overflow — jq CWE-787 7.1 High 2026-06-25
CVE-2026-54679 jq: potential integer overflow in jvp_string_append — jq CWE-190 - - 2026-06-25
CVE-2026-43896 jq: Stack Overflow in Recursive Object Merge — jq CWE-674 6.2 Medium 2026-05-11
CVE-2026-43895 jq: Embedded NUL in jq import paths causes local redaction-policy bypass and preserves sensitive fields in published artifacts — jq CWE-20 4.4 Medium 2026-05-11
CVE-2026-44777 jq: stack overflow in module loading on mutual `include` — jq CWE-674 - - 2026-05-11
CVE-2026-43894 jq: Wild stack write via signed-integer overflow in decNumber D2U() macro — jq CWE-190 6.2 Medium 2026-05-11
CVE-2026-41256 jq: Embedded NUL truncates top-level jq programs loaded with -f — jq CWE-158 5.5 Medium 2026-05-11
CVE-2026-40612 jq: Stack overflow via unbounded recursion in jv_contains — jq CWE-674 - - 2026-05-11
CVE-2026-41257 jq: Signed-int overflow in `stack_reallocate` (jq VM stack) — jq CWE-190 - - 2026-05-11
CVE-2026-33948 jq: Embedded-NUL Truncation in CLI JSON Input Path Causes Prefix-Only Validation of Malformed Input — jq CWE-170 9.8 - 2026-04-13
CVE-2026-40164 jq: Algorithmic complexity DoS via hardcoded MurmurHash3 seed — jq CWE-328 7.5 High 2026-04-13
CVE-2026-39979 jq: Out-of-Bounds Read in jv_parse_sized() Error Formatting for Non-NUL-Terminated Counted Buffers — jq CWE-125 9.8 - 2026-04-13
CVE-2026-39956 jq: Missing runtime type checks for _strindices lead to crash and limited memory disclosure — jq CWE-125 6.1 Medium 2026-04-13
CVE-2026-33947 jq: Unbounded Recursion in jv_setpath(), jv_getpath() and delpaths_sorted() — jq CWE-674 6.2 Medium 2026-04-13
CVE-2026-32316 jq: Integer overflow in jvp_string_append() allows Heap-based Buffer Overflow — jq CWE-122 8.2 High 2026-04-13
CVE-2025-9403 jqlang jq JSON jq_test.c run_jq_tests assertion — jq CWE-617 3.3 Low 2025-08-25
CVE-2025-49014 jq heap use after free vulnerability in f_strflocaltime — jq CWE-416 9.8AI Critical AI 2025-06-19
CVE-2025-48060 AddressSanitizer: stack-buffer-overflow in jq_fuzz_execute (jv_string_vfmt) — jq CWE-121 6.5AI Medium AI 2025-05-21
CVE-2024-23337 jq has signed integer overflow in jv.c:jvp_array_write — jq CWE-190 4.3 Medium 2025-05-21
CVE-2024-53427 jq 安全漏洞 — jq CWE-843 8.1 High 2025-02-26
CVE-2023-50268 jq has stack-based buffer overflow in decNaNs — jq CWE-121 6.2 Medium 2023-12-13
CVE-2023-50246 jq has heap-buffer-overflow vulnerability in the function decToString in decNumber.c — jq CWE-122 6.2 Medium 2023-12-13

This page lists every published CVE security advisory associated with jqlang. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.