ID:12694 - Exploit for Uncontrolled Recursion in jq - CVE-2026-43896

 
Main Vulnerability Database Exploits ID:12694 - Exploit for Uncontrolled Recursion in jq - CVE-2026-43896

ID:12694 - Exploit for Uncontrolled Recursion in jq - CVE-2026-43896

Published: May 6, 2026


Vulnerability identifier: #VU130232
Vulnerability risk: High
CVE-ID: CVE-2026-43896
CWE-ID: CWE-674
Exploitation vector: Remote access
Vulnerable software:
jq

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to uncontrolled recursion in the "jv_object_merge_recursive()" function in src/jv.c. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.