<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T18:44:42.723181+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-54679</id>
    <title>BELL-CVE-2026-54679</title>
    <updated>2026-10-03T18:44:42.736291+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:stream: jq</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-54679"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-330366</id>
    <title>EUVD-2026-330366</title>
    <updated>2026-10-03T18:44:42.736393+00:00</updated>
    <content>EUVD-2026-330366</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-330366"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54679</id>
    <title>fkie_cve-2026-54679</title>
    <updated>2026-10-03T18:44:42.736410+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>jq is a command-line JSON processor. Prior to 1.8.2, on 32bit system, jvp_string_append has a chance of integer/multiple overflowing and then causing a massive buffer overrun.  This vulnerability is fixed in 1.8.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-54679"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-54679</id>
    <title>msrc_CVE-2026-54679 — jq: potential integer overflow in jvp_string_append</title>
    <updated>2026-10-03T18:44:42.736435+00:00</updated>
    <content>msrc_CVE-2026-54679</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-54679"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2803</id>
    <title>OESA-2026-2803 — jq security update</title>
    <updated>2026-10-03T18:44:42.736452+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP4: jq</p>
<p>jq is a lightweight and flexible command-line JSON processor. you can use it to slice and filter and map and transform structured data. It is written in portable C, and it has zero runtime dependencies. it can mangle the data format that you have into the one that you want.

Security Fix(es):</p>
<p>jq is a command-line JSON processor. Prior to 1.8.2, comparing two sufficiently deeply nested arrays with the == operator exhausts the C stack on jq&amp;apos;s ordinary command-line surface, resulting in denial of service via stack exhaustion (uncontrolled recursion). The crash occurs in jq&amp;apos;s recursive structural comparison code, with the recursion repeating through jvp_array_equal() and jv_equal() in src/jv.c when comparing deeply nested arrays; a nearby sort comparator path through jv_cmp() in src/jv_aux.c overflows the stack at a larger nesting depth from  the same missing recursion guard. Anyone running jq comparisons on attacker-controlled deeply nested JSON values, or embedding jq in a context  where untrusted data can reach the == comparison path, is affected. This vulnerability is fixed in 1.8.2.(CVE-2026-47770)</p>
<p>jq is a command-line JSON processor. Prior to 1.8.2,` jq --rawfile` can turn a handled oversized-string error into invalid-state reuse and a real heap out-of-bounds write in assertion-disabled builds. When jv_load_file(raw=1) reads an attacker-controlled file, it repeatedly appends file chunks to the same jv string accumulator. Once jv_string_append_buf() returns jv…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2803"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11133-1</id>
    <title>openSUSE-SU-2026:11133-1 — jq-1.8.2-1.1 on GA media</title>
    <updated>2026-10-03T18:44:42.736493+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>jq-1.8.2-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11133-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:29986</id>
    <title>RHSA-2026:29986 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
    <updated>2026-10-03T18:44:42.736510+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>jq: stack overflow via unbounded recursion in jv_contains jq: embedded NUL truncates top-level jq programs loaded with -f jq: signed-int overflow in stack_reallocate jq: jq: Arbitrary Code Execution or Denial of Service via Signed Integer Overflow jq: embedded NUL in jq import paths causes local redaction-policy bypass and preserves sensitive fields in published artifacts jq: stack overflow in recursive object merge jq: stack overflow in module loading on mutual include jq: jq: Denial of Service via deeply nested array comparison jq: jq: Heap out-of-bounds write via oversized raw file processing jq: jq: Denial of Service via integer overflow and buffer overrun on 32-bit systems</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:29986"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:22597-1</id>
    <title>SUSE-SU-2026:22597-1 — Security update for jq</title>
    <updated>2026-10-03T18:44:42.736537+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for jq</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:22597-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-54679</id>
    <title>UBUNTU-CVE-2026-54679</title>
    <updated>2026-10-03T18:44:42.736552+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: jq, Ubuntu:Pro:16.04:LTS: jq, Ubuntu:Pro:18.04:LTS: jq, Ubuntu:Pro:20.04:LTS: jq, Ubuntu:22.04:LTS: jq, Ubuntu:24.04:LTS: jq, Ubuntu:25.10: jq, Ubuntu:26.04:LTS: jq</p>
<p>jq is a command-line JSON processor. Prior to 1.8.2, on 32bit system, jvp_string_append has a chance of integer/multiple overflowing and then causing a massive buffer overrun.  This vulnerability is fixed in 1.8.2.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-54679"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1927</id>
    <title>WID-SEC-W-2026-1927 — jq: Schwachstelle ermöglicht nicht spezifizierten Angriff</title>
    <updated>2026-10-03T18:44:42.736580+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann eine Schwachstelle in jq ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1927"/>
  </entry>
</feed>
