The jq project disclosed and patched CVE-2026-33947, an unbounded-recursion flaw in jv_setpath(), jv_getpath(), and delpaths_sorted() in src/jv_aux.c that affects versions through 1.8.1. The bug can be triggered with attacker-controlled path arrays of roughly 60,000+ elements, causing stack exhaustion, SIGSEGV, and process termination. Maintainers said the issue bypasses jq's MAX_PARSING_DEPTH safeguard because the malicious path arrays can be built programmatically at runtime rather than during JSON parsing, creating a denial-of-service risk for web services, CI/CD pipelines, shell scripts, and applications embedding libjq that process untrusted input. The flaw was rated Moderate with CVSS 3.1/6.2 and mapped to CWE-674, and a fix was identified in commit fb59f1491058d58bdc3e8dd28f1773d1ac690a1f alongside a GitHub security advisory.
Separately, the ROOT project faced public disclosure of a reported heap buffer overflow in TKey::Streamer and TBasket::ReadBasketBuffers, with maintainers and oss-security moderators noting that the fix was already public in pull request #22377. The mailing-list exchange emphasized that oss-security is no longer the correct channel for requesting CVE assignments, and ROOT contributors directed reporters to the project's GitHub security reporting process for coordinated disclosure. The discussion also noted that the advisory had effectively become public once posted to the list, while participants raised concerns about disclosure quality and the appearance of AI-generated language in vulnerability reports.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
During the oss-security discussion, participants stated that a fix for the ROOT heap buffer overflow was already publicly available in pull request #22377. ROOT users were also directed to the project's GitHub security reporting channel for future vulnerability reports and coordinated disclosure.
A vulnerability affecting ROOT's TKey::Streamer and TBasket::ReadBasketBuffers was publicly discussed on the oss-security mailing list, effectively disclosing the issue. The thread noted that CVE assignment requests should no longer be made through oss-security and referenced an intended advisory timeline tied to CVE assignment or a 90-day disclosure period.
An oss-security mailing list post further discussed CVE-2026-33947, reiterating the denial-of-service impact and the availability of the fix commit. The thread also raised the question of whether stack overflows in command-line programs should routinely receive CVEs unless embedded-library use materially increases risk.
A GitHub security advisory disclosed CVE-2026-33947 in jq, describing how programmatically constructed path arrays can bypass MAX_PARSING_DEPTH and trigger unbounded recursion. The issue was rated Moderate with CVSS 6.2 and identified as a denial-of-service risk for services, scripts, CI/CD pipelines, and applications embedding libjq that process untrusted input.
The jq project addressed an unbounded recursion vulnerability affecting jv_setpath(), jv_getpath(), and delpaths_sorted() in src/jv_aux.c with commit fb59f1491058d58bdc3e8dd28f1773d1ac690a1f. The flaw affects jq versions up to and including 1.8.1 and can cause stack exhaustion and process termination when attacker-controlled path arrays contain roughly 60,000 or more elements.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourceseclists.org
Open sourceseclists.org
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.