Junglewise Threat Intelligence

CVE-2026-43896: jqlang jq stack overflow in jv_object_merge_recursive

CVE-2026-43896 · Severity: medium · CVSS 6.2 · Published 2026-05-11

Technologies: Jqlang Jq. Vendors: Jqlang.

Executive brief

jq is a widely used command-line tool for processing and transforming JSON data. A vulnerability in how it handles nested data structures allows a specially crafted input to crash the application. This can lead to a denial-of-service, potentially disrupting automated workflows or data processing pipelines that rely on jq to handle external data.

Technical details

A stack exhaustion vulnerability exists in jq versions 1.8.1 and earlier due to uncontrolled recursion in the 'jv_object_merge_recursive' function within 'src/jv.c'. The issue is triggered when the '*' operator is used to merge two objects that contain deeply nested structures. Because the function lacks a recursion depth limit, processing highly nested objects (e.g., 75,000 levels deep) exhausts the C call stack, resulting in a segmentation fault. An attacker who can provide a malicious jq script or influence the objects being merged can cause a denial-of-service. As of the advisory date, no patched version has been released.

Affected products

  • jqlang jq <= 1.8.1

Timeline

  • 2026-05-05: advisory: GitHub Security Advisory published by maintainers
  • 2026-05-11: disclosed: NVD publication date

References

Related threats