{"id":"CVE-2023-50268","summary":"jq has stack-based buffer overflow in decNaNs","details":"jq is a command-line JSON processor. Version 1.7 is vulnerable to stack-based buffer overflow in builds using decNumber. Version 1.7.1 contains a patch for this issue.","aliases":["GHSA-7hmr-442f-qc8j"],"modified":"2026-08-12T13:32:46.904892Z","published":"2023-12-13T20:49:54.982Z","related":["openSUSE-SU-2024:13521-1"],"database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-120","CWE-121"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/50xxx/CVE-2023-50268.json"},"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2023/12/15/10"},{"type":"WEB","url":"https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=64771"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/50xxx/CVE-2023-50268.json"},{"type":"ADVISORY","url":"https://github.com/jqlang/jq/security/advisories/GHSA-7hmr-442f-qc8j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-50268"},{"type":"FIX","url":"https://github.com/jqlang/jq/commit/c9a51565214eece8f1053089739aea73145bfd6b"},{"type":"FIX","url":"https://github.com/jqlang/jq/pull/2804"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/jqlang/jq","events":[{"introduced":"11c528d04d76c9b9553781aa76b073e4f40da008"},{"fixed":"c9a51565214eece8f1053089739aea73145bfd6b"}],"database_specific":{"cpe":"cpe:2.3:a:jqlang:jq:1.7:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.7"},{"last_affected":"1.7"}],"source":["CPE_STRING","REFERENCES"]}}],"versions":["1.7","= 1.7","jq-1.7"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-50268.json","vanir_signatures_modified":"2026-08-12T13:32:46Z","vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"22550875515713324128520625183215086364","length":634},"id":"CVE-2023-50268-a2d2ea46","signature_type":"Function","signature_version":"v1","source":"https://github.com/jqlang/jq/commit/c9a51565214eece8f1053089739aea73145bfd6b","target":{"file":"src/jv.c","function":"jvp_number_cmp"}},{"target":{"file":"src/jv.c"},"deprecated":false,"digest":{"line_hashes":["1371753125883065672057533830705252943","216860606710970311303215741001243012159","165464292948581339852936572259524919584","255758938615600683693124477605172127745","245329855745470253622444550787235282293","154994877992986023031708220241328935675","93166843768021528035323026897990025527","132979471927433437070415656838934883298","277305042641553834268379700979743214986","5391192241338951654753776646990161703","165392846152929313379498705231826085965","166852718090386609754714604848746705693"],"threshold":0.9},"id":"CVE-2023-50268-d89c5938","signature_type":"Line","signature_version":"v1","source":"https://github.com/jqlang/jq/commit/c9a51565214eece8f1053089739aea73145bfd6b"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}