CVE-2026-32316Disclosure(jqlang / jq)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch jqlang jq systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

jq is a command-line JSON processor. An integer overflow vulnerability exists through version 1.8.1 within the jvp_string_append() and jvp_string_copy_replace_bad functions, where concatenating strings with a combined length exceeding 2^31 bytes causes a 32-bit unsigned integer overflow in the buffer allocation size calculation, resulting in a drastically undersized heap buffer. Subsequent memory copy operations then write the full string data into this undersized buffer, causing a heap buffer overflow classified as CWE-190 (Integer Overflow) leading to CWE-122 (Heap-based Buffer Overflow). Any system evaluating untrusted jq queries is affected, as an attacker can crash the process or potentially achieve further exploitation through heap corruption by crafting queries that produce extremely large strings. The root cause is the absence of string size bounds checking, unlike arrays and objects which already have size limits. The issue has been addressed in commit e47e56d226519635768e6aab2f38f0ab037c09e5.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122CWE-190

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • jq

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-14); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
jq

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-14: 2Mentions · 2026-06-22: 1Patch / Workaround · 2026-06-22: 1Technical Details · 2026-04-14: 2Technical Details · 2026-06-22: 104-1406-22
Signal classification3 categories
Disclosure
133.3%
General
133.3%
Patch
133.3%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-142
Disclosure1General1
2026-06-221
Patch1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-32316 jq is a command-line JSON processor. An integer overflow vulnerability exists through version 1.8.1 within the jvp_string_append() and jvp_string_copy_replace_bad fun… https://www.cve.org/CVERecord?id=CVE-2026-32316

    Post summary

    The text reports CVE-2026-32316 as an integer overflow in jq’s string functions, affecting versions up to 1.8.1, but provides no exploit, patch, or active exploitation details.

    000101.0K
    57.2K followersView on X
  • Can Artuc@canartuc
    Patch

    jq 1.8.2 arrived June 20, patching 16 CVEs in the command-line JSON processor, including CVE-2026-32316, a heap buffer overflow in jvp_string_append, and CVE-2026-33947, a new path-depth limit that stops a stack overflow. When did you last pin jq's version in CI?

    Post summary

    jq 1.8.2 was released with patches for 16 CVEs, including heap buffer overflow and path‑depth limit bugs, with no exploitation or PoC details mentioned.

    0000039
    173 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-32316 jq is a command-line JSON processor. An integer overflow vulnerability exists through version 1.8.1 within the jvp_string_append() and jvp_string_copy_replace_bad fun… https://www.cve.org/CVERecord?id=CVE-2026-32316 ----- Traducción: CVE-2026-32316 jq … http://infoflow.cloud`

    Post summary

    The tweet supplies straightforward details of an integer overflow vulnerability in jq and links to its CVE record, but it does not discuss PoC, exploits, active use, or patches.

    0000024
    71 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appjqlangjq---

Explore more