Executive brief
jq is a widely used command-line tool and library for processing and transforming JSON data. A vulnerability in how it handles data paths allows an attacker to provide a specially crafted JSON file that causes the program to crash immediately. This can be used to disrupt services, web applications, or automated pipelines that rely on jq to process user-supplied information.
Technical details
The jv_setpath(), jv_getpath(), and delpaths_sorted() functions in src/jv_aux.c use unbounded recursion where the depth is determined by the length of a caller-supplied path array. While jq has a MAX_PARSING_DEPTH to protect the initial JSON parsing stage, these runtime functions lacked similar enforcement. An attacker can bypass parser limits by providing a flat array (e.g., ~65,000 integers) that, when used as a path argument in a jq filter, exhausts the C call stack and triggers a segmentation fault (SIGSEGV). This affects both the jq CLI and applications embedding libjq. The issue is fixed in commit fb59f149 by introducing a MAX_PATH_DEPTH limit of 10,000.
Affected products
- jqlang jq <= 1.8.1
Timeline
- 2026-04-13: advisory: GitHub Security Advisory GHSA-xwrw-4f8h-rjvg published
- 2026-04-13: disclosed
- 2026-04-13: patched: Fixed in commit fb59f1491058d58bdc3e8dd28f1773d1ac690a1f