jq is a command-line JSON processor. In versions up to and including 1.7.1, an integer overflow arises when assigning value using an index of 2147483647, the signed integer limit. This causes a denial of service. Commit de21386681c0df0104a99d9d09db23a9b2a78b1e contains a patch for the issue.
Metrics
Affected Vendors & Products
References
History
Fri, 20 Jun 2025 18:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Jqlang
Jqlang jq |
|
CPEs | cpe:2.3:a:jqlang:jq:*:*:*:*:*:*:*:* | |
Vendors & Products |
Jqlang
Jqlang jq |
Fri, 06 Jun 2025 22:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-125 |
Thu, 22 May 2025 02:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
threat_severity
|
Wed, 21 May 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 21 May 2025 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | jq is a command-line JSON processor. In versions up to and including 1.7.1, an integer overflow arises when assigning value using an index of 2147483647, the signed integer limit. This causes a denial of service. Commit de21386681c0df0104a99d9d09db23a9b2a78b1e contains a patch for the issue. | |
Title | jq has signed integer overflow in jv.c:jvp_array_write | |
Weaknesses | CWE-190 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-05-21T14:34:51.007Z
Updated: 2025-05-21T14:57:18.378Z
Reserved: 2024-01-15T15:19:19.443Z
Link: CVE-2024-23337

Updated: 2025-05-21T14:57:10.804Z

Status : Analyzed
Published: 2025-05-21T15:16:03.920
Modified: 2025-06-20T17:41:15.807
Link: CVE-2024-23337
