CVE-2015-8863: Jq Project Jq

Critical severity, CVSS 9.8. EPSS: 7.3% chance of exploitation in the next 30 days.

Off-by-one error in the tokenadd function in jv_parse.c in jq allows remote attackers to cause a denial of service (crash) via a long JSON-encoded number, which triggers a heap-based buffer overflow.

Affected products

Published 2016-05-06. Last modified 2026-06-17.