CVE detail
CVE-2026-39979
jq is a command-line JSON processor. In commits before 2f09060afab23fe9390cce7cb860b10416e1bf5f, the jv_parse_sized() API in libjq accepts a counted buffer with an explicit length parameter, but its error-handling path formats the input buffer using %s in jv_string_fmt(), which reads until a NUL terminator is found rather than respecting the caller-supplied length. This means that when malformed JSON is passed in a non-NUL-terminated buffer, the error construction logic performs an out-of-bounds read past the end of the buffer. The vulnerability is reachable by any libjq consumer calling jv_parse_sized() with untrusted input, and depending on memory layout, can result in memory disclosure or process termination. The issue has been patched in commit 2f09060afab23fe9390cce7cb860b10416e1bf5f.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 18.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
33 source links · newest first
- CVE-2026-39979 jq: Out-of-Bounds Read in jv_parse_sized() Error Formatting for Non-NUL-Terminated Counted BuffersMicrosoft MSRC
Information published.
vendormsrc.microsoft.comApr 17, 2026, 8:01 AM - https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39979.jsonsecurity.access.redhat.com
No excerpt available.
Vendor Advisorysecurity.access.redhat.comApr 13, 2026, 11:16 PM - https://bugzilla.redhat.com/show_bug.cgi?id=2458077bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comApr 13, 2026, 11:16 PM - https://access.redhat.com/security/cve/CVE-2026-39979access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 13, 2026, 11:16 PM - https://access.redhat.com/errata/RHSA-2026:8579access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 13, 2026, 11:16 PM - https://access.redhat.com/errata/RHSA-2026:34098access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 13, 2026, 11:16 PM - https://access.redhat.com/errata/RHSA-2026:30089access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 13, 2026, 11:16 PM - https://access.redhat.com/errata/RHSA-2026:30088access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 13, 2026, 11:16 PM - https://access.redhat.com/errata/RHSA-2026:30087access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 13, 2026, 11:16 PM - https://access.redhat.com/errata/RHSA-2026:30078access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 13, 2026, 11:16 PM - https://access.redhat.com/errata/RHSA-2026:28887access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 13, 2026, 11:16 PM - https://access.redhat.com/errata/RHSA-2026:26542access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 13, 2026, 11:16 PM - https://access.redhat.com/errata/RHSA-2026:26528access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 13, 2026, 11:16 PM - https://access.redhat.com/errata/RHSA-2026:25181access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 13, 2026, 11:16 PM - https://access.redhat.com/errata/RHSA-2026:25096access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 13, 2026, 11:16 PM - https://access.redhat.com/errata/RHSA-2026:25044access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 13, 2026, 11:16 PM - https://access.redhat.com/errata/RHSA-2026:23245access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 13, 2026, 11:16 PM - https://access.redhat.com/errata/RHSA-2026:23233access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 13, 2026, 11:16 PM - https://access.redhat.com/errata/RHSA-2026:19365access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 13, 2026, 11:16 PM - https://access.redhat.com/errata/RHSA-2026:19151access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 13, 2026, 11:16 PM - https://access.redhat.com/errata/RHSA-2026:18048access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 13, 2026, 11:16 PM - https://access.redhat.com/errata/RHSA-2026:18047access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 13, 2026, 11:16 PM - https://access.redhat.com/errata/RHSA-2026:18046access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 13, 2026, 11:16 PM - https://access.redhat.com/errata/RHSA-2026:18045access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 13, 2026, 11:16 PM - https://access.redhat.com/errata/RHSA-2026:18044access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 13, 2026, 11:16 PM - https://access.redhat.com/errata/RHSA-2026:18043access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 13, 2026, 11:16 PM - https://access.redhat.com/errata/RHSA-2026:18042access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 13, 2026, 11:16 PM - https://access.redhat.com/errata/RHSA-2026:18040access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 13, 2026, 11:16 PM - https://access.redhat.com/errata/RHSA-2026:16693access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 13, 2026, 11:16 PM - https://access.redhat.com/errata/RHSA-2026:16692access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 13, 2026, 11:16 PM - https://access.redhat.com/errata/RHSA-2026:16252access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 13, 2026, 11:16 PM No excerpt available.
Exploitgithub.comApr 13, 2026, 11:16 PMNo excerpt available.
Exploitgithub.comApr 13, 2026, 11:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-39956CVSS 6.1 · Medium
jq is a command-line JSON processor. In commits after 69785bf77f86e2ea1b4a20ca86775916889e91c9, the _strindices builtin in jq's src/builtin.c passes its arguments directly to jv_s…
- CVE-2026-17995CVSS N/A · Unrated
Out of bounds read in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security se…
- CVE-2026-17869CVSS N/A · Unrated
Out of bounds read in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security s…
- CVE-2026-17772CVSS N/A · Unrated
Out of bounds read in WebGL in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security s…
- CVE-2026-17770CVSS N/A · Unrated
Out of bounds read in Media in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox esca…
- CVE-2026-17745CVSS N/A · Unrated
Out of bounds read in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a…