#VU111911 Buffer overflow in jq
Published: June 25, 2025
jq
stedolan (Stephen Dolan)
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error within the node_min_byte_len() function in /vendor/oniguruma/src/regcomp.c in the Oniguruma dependency. A remote attacker can pass a specially crafted input to the application, trigger stack overflow and perform a denial of service (DoS) attack.