सुरक्षा सलाह पर वापस जाएँ

Mojolicious (Mojo::JSON) CVE-2026-14803: Memory Exhaustion via Unbounded Recursion

Mojolicious (Mojo::JSON) is affected by CVE-2026-14803. The pure-Perl implementation of Mojo::JSON in Mojolicious before 9.47 does not limit JSON nesting depth, allowing a small, deeply nested JSON document to trigger unbounded recursion, memory exhaustion, and a process crash. The path is only used when Cpanel::JSON::XS is not installed or MOJO_NO_JSON_XS is set — the Cpanel::JSON::XS fast path already enforces a nesting limit and is not affected. Affected versions: Mojolicious (Mojo::JSON) before 9.47 — pure-Perl decode path only. Fixed in 9.47. CVSS base score: 6.5.

Medium 6.5 CVSS
cPanel AlmaLinux 8 AlmaLinux 9 CentOS 7 CloudLinux 7 CloudLinux 8 CloudLinux 9

प्रभावित संस्करण

Mojolicious (Mojo::JSON) before 9.47 — pure-Perl decode path only

पैच किया गया संस्करण

9.47

डिफ़ॉल्ट अपडेट कमांड

perl -MCpanel::JSON::XS -e 'print "fast path OKn"'

सुधार कमांड

cPanel & WHM (all supported OS)

perl -MCpanel::JSON::XS -e 'print "fast path OKn"'
# cPanel ships the affected fast path by default — if the check above prints "fast path OK", you are not exposed on cPanel's own stack.
# If it errors, or MOJO_NO_JSON_XS is set, update the Perl Mojo stack:
cpanm [email protected]

Generic Perl / Mojolicious hosts

cpanm [email protected]
perl -MMojo::JSON -e 'print Mojo::JSON->VERSION, "n"'

SharedLicense लाइसेंस के तहत इसका अर्थ

Your SharedLicense cPanel license itself is not affected — this is a vulnerability in the pure-Perl Mojo::JSON decoder shipped with Mojolicious, not in licensing. cPanel & WHM ships Cpanel::JSON::XS by default, which enforces a nesting limit and is not affected; only servers running the pure-Perl fallback need the update. Licenses keep working through updates and nothing needs re-issuing or re-activating.

The pure-Perl implementation of Mojo::JSON in Mojolicious before 9.47 does not limit JSON nesting depth, allowing a small, deeply nested JSON document to trigger unbounded recursion, memory exhaustion, and a process crash. The path is only used when Cpanel::JSON::XS is not installed or MOJO_NO_JSON_XS is set — the Cpanel::JSON::XS fast path already enforces a nesting limit and is not affected.

Any application that decodes untrusted JSON through the pure-Perl path (for example Mojo::Message::json reached via $c->req->json) can exhaust process memory and crash. Applications using the Cpanel::JSON::XS backend are not affected because that backend already enforces a nesting limit. This issue is fixed in Mojolicious 9.47.

Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-14803

अक्सर पूछे जाने वाले प्रश्न

What is CVE-2026-14803?
The pure-Perl implementation of Mojo::JSON in Mojolicious before 9.47 does not limit JSON nesting depth, allowing a small, deeply nested JSON document to trigger unbounded recursion, memory exhaustion, and a process crash. The path is only used when Cpanel::JSON::XS is not installed or MOJO_NO_JSON_XS is set — the Cpanel::JSON::XS fast path already enforces a nesting limit and is not affected. Affected versions: Mojolicious (Mojo::JSON) before 9.47 — pure-Perl decode path only. Fixed in 9.47.
Is CVE-2026-14803 being exploited in the wild?
No confirmed public exploitation has been announced at the time of writing. This is a memory-exhaustion denial of service (CVSS 6.5) requiring an attacker to supply deeply nested JSON to a service using the pure-Perl decoder — patch on your normal schedule.
How do I fix CVE-2026-14803?
Upgrade Mojolicious to 9.47 (cpanm [email protected]). On cPanel & WHM the Cpanel::JSON::XS backend is installed by default and already enforces a nesting limit — verify with `perl -MCpanel::JSON::XS -e "print "fast path OKn""` before concluding you are exposed.
Which versions are affected?
Affected: Mojolicious (Mojo::JSON) before 9.47 — pure-Perl decode path only. Update to 9.47 or later.

अपने सिस्टम में भेद्यताओं की जाँच करें

अपना उत्पाद और ऑपरेटिंग सिस्टम चुनें ताकि आपके लिए लागू सटीक फिक्स कमांड देख सकें।

अपना सिस्टम जाँचें