๐Ÿ” CVE Alert

CVE-2026-68914

UNKNOWN 0.0

Mojolicious pure-Perl Mojo::JSON decoder allows memory exhaustion via deeply nested data

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Mojolicious is a real-time web framework for Perl. Prior to 9.47, the pure-Perl implementation of Mojo::JSON does not limit nesting depth when Cpanel::JSON::XS is unavailable or MOJO_NO_JSON_XS is enabled. An attacker who can supply untrusted JSON to decode_json, from_json, or j can submit deeply nested arrays or objects, causing unbounded recursion, memory exhaustion, and a process crash. Applications using the Cpanel::JSON::XS backend are not affected because that backend already enforces a nesting limit. This issue is fixed in version 9.47.

CWE CWE-400 CWE-674
Vendor mojolicious
Product mojo
Published Sep 18, 2026
Stay Ahead of the Next One

Get instant alerts for mojolicious mojo

Be the first to know when new unknown vulnerabilities affecting mojolicious mojo are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

mojolicious / mojo
< 9.47

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/mojolicious/mojo/security/advisories/GHSA-p5qf-qvw8-xgvg github.com: https://github.com/mojolicious/mojo/commit/cc38b0554275c4d84f6b8b49bcbbc1bec2068fe1