Executive brief
jq is a widely used command-line tool for processing and transforming JSON data. A vulnerability in how it handles nested data structures allows a specially crafted input to crash the application. This can lead to a denial-of-service, potentially disrupting automated workflows or data processing pipelines that rely on jq to handle external data.
Technical details
A stack exhaustion vulnerability exists in jq versions 1.8.1 and earlier due to uncontrolled recursion in the 'jv_object_merge_recursive' function within 'src/jv.c'. The issue is triggered when the '*' operator is used to merge two objects that contain deeply nested structures. Because the function lacks a recursion depth limit, processing highly nested objects (e.g., 75,000 levels deep) exhausts the C call stack, resulting in a segmentation fault. An attacker who can provide a malicious jq script or influence the objects being merged can cause a denial-of-service. As of the advisory date, no patched version has been released.
Affected products
- jqlang jq <= 1.8.1
Timeline
- 2026-05-05: advisory: GitHub Security Advisory published by maintainers
- 2026-05-11: disclosed: NVD publication date