CVE-2026-33947Disclosure(jqlang / jq)

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch jqlang jq systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

jq is a command-line JSON processor. In versions 1.8.1 and below, functions jv_setpath(), jv_getpath(), and delpaths_sorted() in jq's src/jv_aux.c use unbounded recursion whose depth is controlled by the length of a caller-supplied path array, with no depth limit enforced. An attacker can supply a JSON document containing a flat array of ~65,000 integers (~200 KB) that, when used as a path argument by a trusted jq filter, exhausts the C call stack and crashes the process with a segmentation fault (SIGSEGV). This bypass works because the existing MAX_PARSING_DEPTH (10,000) limit only protects the JSON parser, not runtime path operations where arrays can be programmatically constructed to arbitrary lengths. The impact is denial of service (unrecoverable crash) affecting any application or service that processes untrusted JSON input through jq's setpath, getpath, or delpaths builtins. This issue has been addressed in commit fb59f1491058d58bdc3e8dd28f1773d1ac690a1f.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-674

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • jq

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-14); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
jq

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-14: 2Mentions · 2026-06-22: 1Patch / Workaround · 2026-06-22: 1Technical Details · 2026-04-14: 2Technical Details · 2026-06-22: 104-1406-22
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-142
Disclosure2
2026-06-221
Patch1
Full discourse3 posts
  • Can Artuc@canartuc
    Patch

    jq 1.8.2 arrived June 20, patching 16 CVEs in the command-line JSON processor, including CVE-2026-32316, a heap buffer overflow in jvp_string_append, and CVE-2026-33947, a new path-depth limit that stops a stack overflow. When did you last pin jq's version in CI?

    Post summary

    The text announces jq 1.8.2 as a fix release that patches 16 CVEs, highlighting two recent vulnerabilities—a heap buffer overflow and a stack overflow mitigation—underscoring the vendor’s patching effort.

    0000039
    173 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33947 jq is a command-line JSON processor. In versions 1.8.1 and below, functions jv_setpath(), jv_getpath(), and delpaths_sorted() in jq's src/jv_aux.c use unbounded recur… https://www.cve.org/CVERecord?id=CVE-2026-33947

    Post summary

    The post announces CVE-2026-33947 as an unbounded recursion flaw in jq versions 1.8.1 and earlier, affecting specific functions, with no mention of PoC, exploit, or patches.

    0000093
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-33947 Stack Exhaustion Denial of Service in jq 1.8.1 and Below https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33947

    Post summary

    A Stack Exhaustion Denial of Service vulnerability (CVE-2026-33947) affecting jq 1.8.1 and earlier has been identified, with details referenced via a vulnerability database link.

    0000030
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appjqlangjq---

Explore more