CVE-2025-49014

MEDIUM

jq <1.8.0 - Use After Free

Title source: llm
STIX 2.1

Description

jq is a command-line JSON processor. In version 1.8.0 a heap use after free vulnerability exists within the function f_strflocaltime of /src/builtin.c. This issue has been patched in commit 499c91b, no known fix version exists at time of publication.

Scores

CVSS v4 5.5
EPSS 0.0039
EPSS Percentile 59.8%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-416
Status published
Products (1)
jqlang/jq = 1.8.0
Published Jun 19, 2025
Tracked Since Feb 18, 2026