Known vulnerabilities in jq (Red Hat package)

Software CPE: cpe:2.3:o:red_hat:jq_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 6
Public exploits: 2
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting jq (Red Hat package) jq (Red Hat package) is affected by 6 known vulnerabilities: 2 high, 3 medium, 1 low Critical High Medium Low

Vulnerabilities (6)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU125832 - Inefficient Algorithmic Complexity
CVE-2026-40164
CWE-407 Medium
Available
No
1.5-12.el8_4.5, 1.6-3.el8_6.2, 1.6-6.el8_8.4, 1.6-12.el8_10, 1.6-12.el9_0.3, 1.6-15.el9_2.3, 1.6-16.el9_4.2, 1.6-17.el9_6.4, 1.6-19.el9_7.0.2, 1.7.1-8.el10_0.3 13.04.2026 SB2026041326
SB2026041653
SB20260417125
and 18 more
#VU125830 - Out-of-bounds read
CVE-2026-39979
CWE-125 High
Available
No
1.5-12.el8_4.5, 1.6-3.el8_6.2, 1.6-6.el8_8.4, 1.6-12.el8_10, 1.6-12.el9_0.3, 1.6-15.el9_2.3, 1.6-16.el9_4.2, 1.6-17.el9_6.4, 1.6-19.el9_7.0.2, 1.7.1-8.el10_0.3 13.04.2026 SB2026041326
SB2026041653
SB20260417125
and 18 more
#VU111913 - Integer overflow
CVE-2024-23337
CWE-190 Medium
No
No
1.5-12.el8_2.1, 1.5-12.el8_4.4, 1.6-3.el8_6.1, 1.6-6.el8_8.3, 1.6-11.el8_10, 1.6-12.el9_0.1, 1.6-15.el9_2.2, 1.6-16.el9_4.1, 1.6-17.el9_6.2 25.06.2025 SB2025032035
SB2025070824
SB2025070826
and 29 more
#VU111912 - Heap-based Buffer Overflow
CVE-2025-48060
CWE-122 Medium
No
No
1.5-12.el8_2.1, 1.5-12.el8_4.4, 1.6-3.el8_6.1, 1.6-6.el8_8.3, 1.6-11.el8_10, 1.6-12.el9_0.1, 1.6-15.el9_2.2, 1.6-16.el9_4.1, 1.6-17.el9_6.2 25.06.2025 SB2025032035
SB2025070824
SB2025070826
and 38 more
#VU62796 - Incorrect Default Permissions
CVE-2022-27652
CWE-276 Low
No
No
1.6-2.el7 04.05.2022 SB2022050416
SB2022050422
SB2022080148
and 1 more
#VU33047 - Heap-based Buffer Overflow
CVE-2015-8863
CWE-122 High
No
No
1.3-3.el7ost 06.05.2016 SB2016052608
SB2016060215
SB2016120807
and 3 more