# jq Security Considerations for Untrusted Input: Architecture and Best Practices

> Learn jq security best practices for untrusted input. Discover how jq protects against malicious JSON with strict validation, isolated I/O, and invalid value propagation. Secure your JSON processing today.

- Repository: [jqlang/jq](https://github.com/jqlang/jq)
- Tags: best-practices
- Published: 2026-04-11

---

**jq prevents malformed or malicious JSON from crashing processes or executing code through strict UTF-8 validation, a dedicated invalid-value propagation system, and isolated I/O abstractions that never trust external data.**

When processing JSON from untrusted sources—external APIs, user uploads, or network streams—security considerations must extend beyond simple syntax validation. The `jq` processor treats all input as potentially hostile, implementing a defense-in-depth architecture that confines parsing errors and prevents memory corruption. By examining the source implementation in [`src/parser.c`](https://github.com/jqlang/jq/blob/main/src/parser.c), [`src/jv.c`](https://github.com/jqlang/jq/blob/main/src/jv.c), and `src/util