CVE-2026-68914
Mojolicious pure-Perl Mojo::JSON decoder allows memory exhaustion via deeply nested data
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Mojolicious is a real-time web framework for Perl. Prior to 9.47, the pure-Perl implementation of Mojo::JSON does not limit nesting depth when Cpanel::JSON::XS is unavailable or MOJO_NO_JSON_XS is enabled. An attacker who can supply untrusted JSON to decode_json, from_json, or j can submit deeply nested arrays or objects, causing unbounded recursion, memory exhaustion, and a process crash. Applications using the Cpanel::JSON::XS backend are not affected because that backend already enforces a nesting limit. This issue is fixed in version 9.47.
| CWE | CWE-400 CWE-674 |
| Vendor | mojolicious |
| Product | mojo |
| Published | Sep 18, 2026 |
Stay Ahead of the Next One
Get instant alerts for mojolicious mojo
Be the first to know when new unknown vulnerabilities affecting mojolicious mojo are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
mojolicious / mojo
< 9.47