A vulnerability was determined in jqlang jq up to 1.6. Impacted is the function run_jq_tests of the file jq_test.c of the component JSON Parser. Executing manipulation can lead to reachable assertion. The attack requires local access. The exploit has been publicly disclosed and may be utilized. Other versions might be affected as well.
Conclusion & alert: CVE-2025-9403 is rated Exploit Available (50/100): CVSS Low severity, with low exploitation likelihood (EPSS 0.01%). Core evidence: 3 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ | |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ | |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-08-25 | — | 0.01% | — |
Full EPSS history (1 record total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 1.9 | 4.0 | LOW |
|
— | — | [email protected] |
| 3.3 | 3.1 | LOW |
|
1.8 | 1.4 | [email protected] |
| 5.5 | 3.1 | MEDIUM |
|
1.8 | 3.6 | [email protected] |
| 1.7 | 2.0 | LOW |
|
3.1 | 2.9 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
— | CVE-2025-9403: 1 source package rows (jq); 5 state rows across 5 repos (3.19-main, 3.20-main, 3.21-main, 3.22-main, edge-main); fixed 0, open 5. | https://security.alpinelinux.org/vuln/CVE-2025-9403 |
debian
|
unimportant | CVE-2025-9403 unimportant priority: Debian including 1 source packages (jq), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): open 5. | https://security-tracker.debian.org/tracker/CVE-2025-9403 |
redhat
|
low | — | https://access.redhat.com/security/cve/CVE-2025-9403 |
suse
|
low | CVE-2025-9403 severity low: SUSE including 3 source package names (jq, libjq-devel, libjq1), 12 product×package rows across 5 product lines (SUSE Linux Enterprise Server 16.0, SUSE Linux Enterprise Server for SAP applications 16.0, … (5 product lines)): Known Not Affected 12. | https://www.suse.com/security/cve/CVE-2025-9403/ |
ubuntu
|
negligible | CVE-2025-9403 negligible priority: Ubuntu including 1 source packages (jq), 9 status rows across 9 suites (bionic, focal, jammy, noble, plucky, questing, trusty, upstream, xenial): needs-triage 8, ignored 1. | https://ubuntu.com/security/CVE-2025-9403 |
| URL | Tags |
|---|---|
| https://drive.google.com/file/d/1r8m9PhU_rk-QPj6OMcs415FcvWPD-zJY/view?usp=sharing | Exploit |
| https://github.com/jqlang/jq/issues/3393 | Exploit Issue Tracking Vendor Advisory |
| https://vuldb.com/?ctiid.321239 | Permissions Required VDB Entry |
| https://vuldb.com/?id.321239 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.633170 | Exploit Third Party Advisory VDB Entry |