Description
Cpanel::JSON::XS before version 4.40 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified impact
Published: 2025-09-08
Score: 5.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Update to 4.40 or later, or apply the provided patch

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4318-1 libcpanel-json-xs-perl security update
Debian DSA Debian DSA DSA-6000-1 libcpanel-json-xs-perl security update
EUVD EUVD EUVD-2025-27140 Cpanel::JSON::XS before version 4.40 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified impact
Ubuntu USN Ubuntu USN USN-7749-1 Cpanel-JSON-XS vulnerability
History

Tue, 04 Nov 2025 22:30:00 +0000

Type Values Removed Values Added
References

Mon, 03 Nov 2025 19:30:00 +0000

Type Values Removed Values Added
References

Tue, 09 Sep 2025 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Rurban
Rurban cpanel::json::xs
Vendors & Products Rurban
Rurban cpanel::json::xs

Mon, 08 Sep 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 08 Sep 2025 15:15:00 +0000

Type Values Removed Values Added
Description Cpanel::JSON::XS before version 4.40 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified impact
Title Cpanel::JSON::XS before version 4.40 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified impact
Weaknesses CWE-122
References

Subscriptions

Rurban Cpanel::json::xs
cve-icon MITRE

Status: PUBLISHED

Assigner: CPANSec

Published:

Updated: 2025-11-04T21:10:23.342Z

Reserved: 2025-04-16T09:05:34.363Z

Link: CVE-2025-40929

cve-icon Vulnrichment

Updated: 2025-11-04T21:10:23.342Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-09-08T15:15:35.957

Modified: 2025-11-04T22:16:12.663

Link: CVE-2025-40929

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-09-09T21:32:03Z

Weaknesses