AZL-105069

See a problem?
Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105069.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-105069
Upstream
Published
2026-09-24T14:18:21Z
Modified
2026-10-02T05:31:52Z
Summary
CVE-2026-97058 affecting package js-jquery 3.5.0-4
Details

sprintf-js through 1.1.3 passes unbounded precision specifiers to toFixed, toExponential, and toPrecision methods without validation, causing uncaught RangeError exceptions. Attackers who control format strings can inject precision values exceeding ECMAScript limits to abort calling operations with minimal payload.

References

Affected packages

Azure Linux:3 / js-jquery

Package

Name
js-jquery
Purl
pkg:rpm/azure-linux/js-jquery

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
3.5.0-4

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105069.json"