Mojolicious (Mojo::JSON) CVE-2026-14803: Memory Exhaustion via Unbounded Recursion
Mojolicious (Mojo::JSON) is affected by CVE-2026-14803. The pure-Perl implementation of Mojo::JSON in Mojolicious before 9.47 does not limit JSON nesting depth, allowing a small, deeply nested JSON document to trigger unbounded recursion, memory exhaustion, and a process crash. The path is only used when Cpanel::JSON::XS is not installed or MOJO_NO_JSON_XS is set — the Cpanel::JSON::XS fast path already enforces a nesting limit and is not affected. Affected versions: Mojolicious (Mojo::JSON) before 9.47 — pure-Perl decode path only. Fixed in 9.47. CVSS base score: 6.5.
Versiones afectadas
Mojolicious (Mojo::JSON) before 9.47 — pure-Perl decode path only
Versión parcheada
9.47
CMD de actualización por defecto
perl -MCpanel::JSON::XS -e 'print "fast path OKn"'
Comandos de corrección
cPanel & WHM (all supported OS)
perl -MCpanel::JSON::XS -e 'print "fast path OKn"'
# cPanel ships the affected fast path by default — if the check above prints "fast path OK", you are not exposed on cPanel's own stack.
# If it errors, or MOJO_NO_JSON_XS is set, update the Perl Mojo stack:
cpanm [email protected]
Generic Perl / Mojolicious hosts
cpanm [email protected]
perl -MMojo::JSON -e 'print Mojo::JSON->VERSION, "n"'
Lo que esto significa bajo una licencia de SharedLicense
Your SharedLicense cPanel license itself is not affected — this is a vulnerability in the pure-Perl Mojo::JSON decoder shipped with Mojolicious, not in licensing. cPanel & WHM ships Cpanel::JSON::XS by default, which enforces a nesting limit and is not affected; only servers running the pure-Perl fallback need the update. Licenses keep working through updates and nothing needs re-issuing or re-activating.
The pure-Perl implementation of Mojo::JSON in Mojolicious before 9.47 does not limit JSON nesting depth, allowing a small, deeply nested JSON document to trigger unbounded recursion, memory exhaustion, and a process crash. The path is only used when Cpanel::JSON::XS is not installed or MOJO_NO_JSON_XS is set — the Cpanel::JSON::XS fast path already enforces a nesting limit and is not affected.
Any application that decodes untrusted JSON through the pure-Perl path (for example Mojo::Message::json reached via $c->req->json) can exhaust process memory and crash. Applications using the Cpanel::JSON::XS backend are not affected because that backend already enforces a nesting limit. This issue is fixed in Mojolicious 9.47.
Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-14803
Preguntas frecuentes
What is CVE-2026-14803?
Is CVE-2026-14803 being exploited in the wild?
How do I fix CVE-2026-14803?
Which versions are affected?
Referencias
Comprueba tu sistema en busca de vulnerabilidades
Selecciona tu producto y sistema operativo para ver los comandos de corrección exactos que se aplican a ti.
Comprueba tu sistema