Вернуться к предупреждениям о безопасности

Mojolicious (Mojo::JSON) CVE-2026-14803: Memory Exhaustion via Unbounded Recursion

Mojolicious (Mojo::JSON) is affected by CVE-2026-14803. The pure-Perl implementation of Mojo::JSON in Mojolicious before 9.47 does not limit JSON nesting depth, allowing a small, deeply nested JSON document to trigger unbounded recursion, memory exhaustion, and a process crash. The path is only used when Cpanel::JSON::XS is not installed or MOJO_NO_JSON_XS is set — the Cpanel::JSON::XS fast path already enforces a nesting limit and is not affected. Affected versions: Mojolicious (Mojo::JSON) before 9.47 — pure-Perl decode path only. Fixed in 9.47. CVSS base score: 6.5.

Medium 6.5 CVSS
cPanel AlmaLinux 8 AlmaLinux 9 CentOS 7 CloudLinux 7 CloudLinux 8 CloudLinux 9

Затронутые версии

Mojolicious (Mojo::JSON) before 9.47 — pure-Perl decode path only

Исправленная версия

9.47

Команда обновления по умолчанию

perl -MCpanel::JSON::XS -e 'print "fast path OKn"'

Команды исправления

cPanel & WHM (all supported OS)

perl -MCpanel::JSON::XS -e 'print "fast path OKn"'
# cPanel ships the affected fast path by default — if the check above prints "fast path OK", you are not exposed on cPanel's own stack.
# If it errors, or MOJO_NO_JSON_XS is set, update the Perl Mojo stack:
cpanm [email protected]

Generic Perl / Mojolicious hosts

cpanm [email protected]
perl -MMojo::JSON -e 'print Mojo::JSON->VERSION, "n"'

Что это значит по лицензии SharedLicense

Your SharedLicense cPanel license itself is not affected — this is a vulnerability in the pure-Perl Mojo::JSON decoder shipped with Mojolicious, not in licensing. cPanel & WHM ships Cpanel::JSON::XS by default, which enforces a nesting limit and is not affected; only servers running the pure-Perl fallback need the update. Licenses keep working through updates and nothing needs re-issuing or re-activating.

The pure-Perl implementation of Mojo::JSON in Mojolicious before 9.47 does not limit JSON nesting depth, allowing a small, deeply nested JSON document to trigger unbounded recursion, memory exhaustion, and a process crash. The path is only used when Cpanel::JSON::XS is not installed or MOJO_NO_JSON_XS is set — the Cpanel::JSON::XS fast path already enforces a nesting limit and is not affected.

Any application that decodes untrusted JSON through the pure-Perl path (for example Mojo::Message::json reached via $c->req->json) can exhaust process memory and crash. Applications using the Cpanel::JSON::XS backend are not affected because that backend already enforces a nesting limit. This issue is fixed in Mojolicious 9.47.

Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-14803

Часто задаваемые вопросы

What is CVE-2026-14803?
The pure-Perl implementation of Mojo::JSON in Mojolicious before 9.47 does not limit JSON nesting depth, allowing a small, deeply nested JSON document to trigger unbounded recursion, memory exhaustion, and a process crash. The path is only used when Cpanel::JSON::XS is not installed or MOJO_NO_JSON_XS is set — the Cpanel::JSON::XS fast path already enforces a nesting limit and is not affected. Affected versions: Mojolicious (Mojo::JSON) before 9.47 — pure-Perl decode path only. Fixed in 9.47.
Is CVE-2026-14803 being exploited in the wild?
No confirmed public exploitation has been announced at the time of writing. This is a memory-exhaustion denial of service (CVSS 6.5) requiring an attacker to supply deeply nested JSON to a service using the pure-Perl decoder — patch on your normal schedule.
How do I fix CVE-2026-14803?
Upgrade Mojolicious to 9.47 (cpanm [email protected]). On cPanel & WHM the Cpanel::JSON::XS backend is installed by default and already enforces a nesting limit — verify with `perl -MCpanel::JSON::XS -e "print "fast path OKn""` before concluding you are exposed.
Which versions are affected?
Affected: Mojolicious (Mojo::JSON) before 9.47 — pure-Perl decode path only. Update to 9.47 or later.

Проверьте систему на уязвимости

Выберите продукт и операционную систему, чтобы увидеть точные команды исправления.

Проверьте свою систему