itchyny
6 exploits
Active since May 2025
jq: Unbounded Recursion in jv_setpath(), jv_getpath() and delpaths_sorted()
CVSS 6.2
jq: Embedded-NUL Truncation in CLI JSON Input Path Causes Prefix-Only Validation of Malformed Input
CVSS 5.3
jq: Out-of-Bounds Read in jv_parse_sized() Error Formatting for Non-NUL-Terminated Counted Buffers
CVSS 6.5
jq: Algorithmic complexity DoS via hardcoded MurmurHash3 seed
CVSS 7.5
jq: Integer overflow in jvp_string_append() allows Heap-based Buffer Overflow
CVSS 8.2
JQ < 1.7.1 - Integer Overflow
CVSS 4.3