Skip to content

jq: CVE-2024-53427 & CVE-2025-48060 #411881

@h0nIg

Description

@h0nIg

Nixpkgs version

  • Stable (25.05)

Describe the bug

CVE-2024-53427 (8.1 score) and CVE-2025-48060 (7.7 score) should get patched, as the maintainer does not plan to provide a near-future release: jqlang/jq#3315

https://nvd.nist.gov/vuln/detail/CVE-2024-53427
https://nvd.nist.gov/vuln/detail/CVE-2025-48060

Steps to reproduce

see

Expected behaviour

patched

Screenshots

No response

Relevant log output

Additional context

No response

System metadata

25.05

Notify maintainers

@raskin
@Artturin
@ncfavier


Note for maintainers: Please tag this issue in your pull request description. (i.e. Resolves #ISSUE.)

I assert that this issue is relevant for Nixpkgs

Is this issue important to you?

Add a 👍 reaction to issues you find important.

Metadata

Metadata

Assignees

No one assigned

    Labels

    0.kind: bugSomething is broken1.severity: securityIssues which raise a security issue, or PRs that fix one
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions