PT-2026-95475 · Unknown · Mojolicious
CVE-2026-68914
·
Published
2026-09-18
·
Updated
2026-09-24
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Mojolicious versions prior to 9.47
Description
The pure-Perl implementation of Mojo::JSON fails to limit nesting depth when the
MOJO NO JSON XS variable is enabled or when Cpanel::JSON::XS is unavailable. An attacker can provide untrusted JSON to the decode json(), from json(), or j() functions containing deeply nested arrays or objects. This leads to unbounded recursion, memory exhaustion, and a subsequent process crash.Recommendations
Update to version 9.47.
As a temporary mitigation, ensure the Cpanel::JSON::XS backend is available and active, as it enforces nesting limits.
Exploit
Fix
Uncontrolled Recursion
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mojolicious