jq is a command-line JSON processor. In commits before 2f09060afab23fe9390cce7cb860b10416e1bf5f, the jv_parse_sized() API in libjq accepts a counted buffer with an explicit length parameter, but its error-handling path formats the input buffer using %s in jv_string_fmt(), which reads until a NUL terminator is found rather than respecting the caller-supplied length. This means that when malformed JSON is passed in a non-NUL-terminated buffer, the error construction logic performs an out-of-bounds read past the end of the buffer. The vulnerability is reachable by any libjq consumer calling jv_parse_sized() with untrusted input, and depending on memory layout, can result in memory disclosure or process termination. The issue has been patched in commit 2f09060afab23fe9390cce7cb860b10416e1bf5f.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-125"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/39xxx/CVE-2026-39979.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"fixed": "2f09060afab23fe9390cce7cb860b10416e1bf5f"
}
],
"source": "AFFECTED_FIELD"
},
{
"extracted_events": [
{
"fixed": "2f09060afab23fe9390cce7cb860b10416e1bf5f"
}
],
"source": "DESCRIPTION"
}
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-39979.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "199510934960573295006688652191971625366",
"length": 846
},
"id": "CVE-2026-39979-05ddb4a8",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/jqlang/jq/commit/2f09060afab23fe9390cce7cb860b10416e1bf5f",
"target": {
"file": "src/jv_parse.c",
"function": "jv_parse_sized_custom_flags"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"159327352766948974014880466537272337191",
"206613873127793645204435291849754007209",
"187473737466624667232140801196719577201",
"168730623363307008103535459005129738467",
"220339632937479546282868978076064728579"
],
"threshold": 0.9
},
"id": "CVE-2026-39979-be1b7201",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/jqlang/jq/commit/2f09060afab23fe9390cce7cb860b10416e1bf5f",
"target": {
"file": "src/jv_parse.c"
}
}
]
"2026-08-12T16:23:59Z"