pkg:Debian/jq

25 total CVEsCRITICAL1HIGH7MEDIUM15

✅ Check your installed version

All known vulnerabilities

  • CRITICAL9.8CVE-2015-8863Off-by-one error in the tokenadd function in jv_parse.c in jq allows remote attackers to cause a denial of service (crash) via a long JSON-…
    from 0, < 1.5+dfsg-1.1
  • HIGH8.1CVE-2024-53427decNumberCopy in decNumber.c in jq through 1.7.1 does not properly consider that NaN is interpreted as numeric, which has a resultant stack…
    from 0, < 1.7.1-5
  • HIGH7.5CVE-2026-40164jq is a command-line JSON processor.
    from 0, < 1.6-2.1+deb11u2
  • HIGH7.5CVE-2026-32316jq is a command-line JSON processor.
    from 0, < 1.6-2.1+deb11u2
  • HIGH7.5CVE-2025-48060jq - security update
    from 0, < 1.6-2.1+deb11u1
  • HIGH7.5CVE-2025-48060jq - security update
    from 0, < 1.6-2.1+deb11u1
  • HIGH7.5CVE-2023-49355decToString in decNumber/decNumber.c in jq 88f01a7 has a one-byte out-of-bounds write via the " []-1.2e-1111111111" input.
    from 0, < 1.7.1-1
  • HIGH7.5CVE-2016-4074The jv_dump_term function in jq 1.5 allows remote attackers to cause a denial of service (stack consumption and application crash) via a cr…
    from 0, < 1.5+dfsg-1.1
  • MEDIUM6.5CVE-2026-39979jq is a command-line JSON processor.
    from 0, < 1.6-2.1+deb11u2
  • MEDIUM6.5CVE-2024-23337jq is a command-line JSON processor.
    from 0
  • MEDIUM6.1CVE-2026-39956jq is a command-line JSON processor.
    from 0, < 1.6-2.1+deb11u2
  • MEDIUM5.5CVE-2026-44777jq is a command-line JSON processor.
    from 0, < 1.6-2.1+deb11u2
  • MEDIUM5.5CVE-2026-43896jq is a command-line JSON processor.
    from 0, < 1.6-2.1+deb11u2
  • MEDIUM5.5CVE-2026-43894jq is a command-line JSON processor.
    from 0
  • MEDIUM5.5CVE-2026-41257jq is a command-line JSON processor.
    from 0, < 1.6-2.1+deb11u2
  • MEDIUM5.5CVE-2026-41256jq is a command-line JSON processor.
    from 0, < 1.6-2.1+deb11u2
  • MEDIUM5.5CVE-2026-40612jq is a command-line JSON processor.
    from 0
  • MEDIUM5.5CVE-2026-33947jq is a command-line JSON processor.
    from 0, < 1.6-2.1+deb11u2
  • MEDIUM5.5CVE-2025-9403A vulnerability was determined in jqlang jq up to 1.6.
    from 0
  • MEDIUM5.5CVE-2023-50268jq is a command-line JSON processor.
    from 0, < 1.7.1-1
  • MEDIUM5.5CVE-2023-50246jq is a command-line JSON processor.
    from 0, < 1.7.1-1
  • MEDIUM5.3CVE-2026-33948jq is a command-line JSON processor.
    from 0, < 1.6-2.1+deb11u2
  • MEDIUM4.4CVE-2026-43895jq is a command-line JSON processor.
    from 0, < 1.6-2.1+deb11u2
  • CVE-2026-47770(no summary)
    from 0
  • CVE-2025-49014jq is a command-line JSON processor.
    from 0, < 1.8.1-1