Direct Vulnerabilities

Known vulnerabilities in the jq package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
CVE-2026-54679

<1.7.1-6+deb13u3
  • L
CVE-2026-49839

<1.7.1-6+deb13u3
  • M
Uncontrolled Recursion

<1.7.1-6+deb13u3
  • M
Integer Overflow or Wraparound

<1.7.1-6+deb13u3
  • M
Uncontrolled Recursion

<1.7.1-6+deb13u3
  • L
Improper Input Validation

<1.7.1-6+deb13u3
  • M
Uncontrolled Recursion

<1.7.1-6+deb13u3
  • M
Integer Overflow or Wraparound

<1.7.1-6+deb13u3
  • M
Uncontrolled Recursion

<1.7.1-6+deb13u3
  • L
Improper Neutralization of Null Byte or NUL Character

<1.7.1-6+deb13u3
  • M
Out-of-bounds Read

<1.7.1-6+deb13u2
  • M
Improper Input Validation

<1.7.1-6+deb13u2
  • M
Uncontrolled Recursion

<1.7.1-6+deb13u2
  • L
Out-of-bounds Read

<1.7.1-6+deb13u2
  • L
Reversible One-Way Hash

<1.7.1-6+deb13u2
  • H
Heap-based Buffer Overflow

<1.7.1-6+deb13u3
  • L
Reachable Assertion

*
  • L
Integer Overflow or Wraparound

<1.7.1-6
  • H
Out-of-bounds Write

<1.7.1-6+deb13u1
  • L
CVE-2024-53427

<1.7.1-6+deb13u3
  • H
Out-of-bounds Write

<1.7.1-1
  • M
Out-of-bounds Write

<1.7.1-1
  • M
Out-of-bounds Write

<1.7.1-1
  • L
Out-of-Bounds

<1.5+dfsg-1.1
  • L
Allocation of Resources Without Limits or Throttling

<1.5+dfsg-1.1