Description
Mojo::JSON versions before 9.47 for Perl allow memory exhaustion via unbounded recursion in the pure-Perl decoder.

The pure-Perl decode path (`_decode_value` dispatching to `_decode_array` and `_decode_object`) recurses with no depth limit, so a small deeply nested JSON document can consume excessive memory.

This path is the default when Cpanel::JSON::XS is not installed or `MOJO_NO_JSON_XS=1` is set; the Cpanel::JSON::XS fast path is not affected.

Any caller that decodes an untrusted JSON body, for example `Mojo::Message::json` reached through `$c->req->json`, can exhaust process memory and cause denial of service.
Published: 2026-07-06
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Mojo::JSON versions prior to 9.47 for Perl contain an unbounded recursion in the pure‑Perl JSON decoder, causing memory exhaustion when a deeply nested JSON document is parsed. The recursion depth is unchecked, so an attacker can send a crafted JSON payload that consumes increasing amounts of interpreter memory, potentially resulting in process termination or a denial of service. The vulnerability is identified as CWE‑674 and affects only the pure‑Perl decoder, which is used by default unless Cpanel::JSON::XS is installed or the MOJO_NO_JSON_XS environment variable is set.

Affected Systems

The library SRI:Mojo::JSON, part of the Mojolicious framework, is affected. All releases before version 9.47 are impacted. Applications that invoke Mojo::Message::json or $c->req->json rely on the default pure‑Perl decoder unless Cpanel::JSON::XS is installed or the environment variable MOJO_NO_JSON_XS is set to 1. These applications, such as web services handling untrusted JSON bodies, are at risk when the fast JSON XS path is not active.

Risk and Exploitability

The CVSS score of 6.5 indicates medium severity, while the EPSS score of less than 1% suggests a low probability. The vulnerability is not listed in the CISA KEV catalog. Based on the description, an attacker can trigger the denial of service by sending a maliciously nested JSON payload. The likely attack vector is an HTTP request that the application processes through Mojo::JSON; this is inferred from the mention that untrusted JSON bodies are parsed via $c->req->json, but the exact transport mechanism is not explicitly stated.

Generated by OpenCVE AI on August 1, 2026 at 19:03 UTC.

Remediation

Vendor Solution

Upgrade to Mojolicious 9.47 or later.


Vendor Workaround

Where upgrading is not possible, install Cpanel::JSON::XS in the include path and leave `MOJO_NO_JSON_XS` unset.


OpenCVE Recommended Actions

  • Upgrade Mojolicious to version 9.47 or later to apply the decoder recursion limit fix.
  • If upgrading is not available, install the Cpanel::JSON::XS module in the application's include path.
  • Ensure the environment variable MOJO_NO_JSON_XS is unset or set to 0 so that the fast XS path is used by default.

Generated by OpenCVE AI on August 1, 2026 at 19:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Sri
Sri mojo::json
Vendors & Products Sri
Sri mojo::json

Mon, 06 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Description Mojo::JSON versions before 9.47 for Perl allow memory exhaustion via unbounded recursion in the pure-Perl decoder. The pure-Perl decode path (`_decode_value` dispatching to `_decode_array` and `_decode_object`) recurses with no depth limit, so a small deeply nested JSON document can consume excessive memory. This path is the default when Cpanel::JSON::XS is not installed or `MOJO_NO_JSON_XS=1` is set; the Cpanel::JSON::XS fast path is not affected. Any caller that decodes an untrusted JSON body, for example `Mojo::Message::json` reached through `$c->req->json`, can exhaust process memory and cause denial of service.
Title Mojo::JSON versions before 9.47 for Perl allow memory exhaustion via unbounded recursion in the pure-Perl decoder
Weaknesses CWE-674
References

cve-icon MITRE

Status: PUBLISHED

Assigner: CPANSec

Published:

Updated: 2026-07-06T18:51:14.358Z

Reserved: 2026-07-05T21:23:29.979Z

Link: CVE-2026-14803

cve-icon Vulnrichment

Updated: 2026-07-06T05:27:01.702Z

cve-icon NVD

Status : Deferred

Published: 2026-07-06T02:16:21.683

Modified: 2026-07-06T19:16:59.597

Link: CVE-2026-14803

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T19:15:04Z

Weaknesses