PT-2026-32565 · Jq+4 · Jq+4

·

CVE-2026-40164

·

Published

2026-04-13

·

Updated

2026-07-14

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions jq versions prior to commit 0c7d133c3c7e37c00b6d46b658a02244fdd3c784
Description The software used MurmurHash3 with a hardcoded, publicly visible seed (0x432A9843) for all JSON object hash table operations. This allows an attacker to precompute key collisions offline and supply a crafted JSON object where all keys hash to the same bucket. Consequently, hash table lookups degrade from O(1) to O(n), transforming jq expressions into O(n²) operations and causing significant CPU exhaustion. This issue impacts CI/CD pipelines, web services, and data processing scripts.
Recommendations Update to the version containing commit 0c7d133c3c7e37c00b6d46b658a02244fdd3c784.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:16252
ALSA-2026:16692
ALSA-2026:16693
ALSA-2026:19151
ALSA-2026:19365
BDU:2026-05546
CVE-2026-40164
ECHO-472E-DB5D-AF63
GHSA-WWJ8-GXM6-JC29
OESA-2026-1981
OPENSUSE-SU-2026:10850-1
OPENSUSE-SU-2026:21248-1
RHSA-2026:19151
RHSA-2026:19365
RHSA-2026:8579
SUSE-SU-2026:22545-1
SUSE-SU-2026:22566-1
SUSE-SU-2026:22664-1
SUSE-SU-2026:22705-1
SUSE-SU-2026:2983-1
USN-8202-1
USN-8202-2
USN-8202-3

Affected Products

Linuxmint
Red Os
Rocky Linux
Ubuntu
Jq