ID:12581 - Exploit for Uncontrolled Recursion in jq - CVE-2026-33947

 
Main Vulnerability Database Exploits ID:12581 - Exploit for Uncontrolled Recursion in jq - CVE-2026-33947

ID:12581 - Exploit for Uncontrolled Recursion in jq - CVE-2026-33947

Published: April 13, 2026


Vulnerability identifier: #VU125831
Vulnerability risk: Medium
CVE-ID: CVE-2026-33947
CWE-ID: CWE-674
Exploitation vector: Remote access
Vulnerable software:
jq

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to uncontrolled recursion in the "jv_setpath()", "jv_getpath()" and "delpaths_sorted()" functions in src/jv_aux.c. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.