
CVE-2026-43894 jq is a command-line JSON processor. In 1.8.1 and earlier, when decNumberFromString is given a number literal of INT_MAX-1 (2147483646) digits, the D2U() macro overfl… https://www.cve.org/CVERecord?id=CVE-2026-43894
Post summary
The text announces a new overflow vulnerability in jq 1.8.1 and earlier, describing the conditions that trigger it.
