CVE-2015-8863: Jq Project Jq
Critical severity, CVSS 9.8. EPSS: 7.3% chance of exploitation in the next 30 days.
Off-by-one error in the tokenadd function in jv_parse.c in jq allows remote attackers to cause a denial of service (crash) via a long JSON-encoded number, which triggers a heap-based buffer overflow.
Affected products
- Jq Project Jq: up to and including 1.5
- Opensuse Leap: version 42.1 only
- Opensuse Opensuse: version 13.2 only
Published 2016-05-06. Last modified 2026-06-17.