PT-2026-95475 · Unknown · Mojolicious

CVE-2026-68914

·

Published

2026-09-18

·

Updated

2026-09-24

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Mojolicious versions prior to 9.47
Description The pure-Perl implementation of Mojo::JSON fails to limit nesting depth when the MOJO NO JSON XS variable is enabled or when Cpanel::JSON::XS is unavailable. An attacker can provide untrusted JSON to the decode json(), from json(), or j() functions containing deeply nested arrays or objects. This leads to unbounded recursion, memory exhaustion, and a subsequent process crash.
Recommendations Update to version 9.47. As a temporary mitigation, ensure the Cpanel::JSON::XS backend is available and active, as it enforces nesting limits.

Exploit

Fix

Uncontrolled Recursion

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-68914
GHSA-P5QF-QVW8-XGVG
OPENSUSE-SU-2026:11850-1
OPENSUSE-SU-2026:21956-1

Affected Products

Mojolicious