Description
Mojo::JSON versions before 9.47 for Perl allow memory exhaustion via unbounded recursion in the pure-Perl decoder.

The pure-Perl decode path (`_decode_value` dispatching to `_decode_array` and `_decode_object`) recurses with no depth limit, so a small deeply nested JSON document can consume excessive memory.

This path is the default when Cpanel::JSON::XS is not installed or `MOJO_NO_JSON_XS=1` is set; the Cpanel::JSON::XS fast path is not affected.

Any caller that decodes an untrusted JSON body, for example `Mojo::Message::json` reached through `$c->req->json`, can exhaust process memory and cause denial of service.
Published: 2026-07-06
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Mojo::JSON versions prior to 9.47 for Perl contain an unbounded recursion in the pure‑Perl JSON decoder, causing memory exhaustion when a deeply nested JSON document is parsed. The recursion depth is unchecked, so an attacker can send a crafted JSON payload that consumes increasing amounts of interpreter memory, potentially resulting in process termination or a denial of service. The vulnerability is identified as CWE‑674 and affects only the pure‑Perl decoder, which is used by default unless Cpanel::JSON::XS is installed or the MOJO_NO_JSON_XS environment variable is set.

Affected Systems

The library SRI:Mojo::JSON, part of the Mojolicious framework, is affected. All releases before version 9.47 are impacted. Applications that invoke Mojo::Message::json or $c->req->json rely on the default pure‑Perl decoder unless Cpanel::JSON::XS is installed or the environment variable MOJO_NO_JSON_XS is not set to 1. These applications, such as web services handling untrusted JSON bodies, are at risk when the fast JSON XS path is not active.

Risk and Exploitability

The CVSS score of 6.5 indicates medium severity, while the EPSS score of less than 1% suggests a low probability. The vulnerability is not listed in the CISA KEV catalog. An attacker can trigger the denial of service by sending a maliciously nested JSON payload in an HTTP request that the application processes through Mojo::JSON. Because the pure‑ is used by default, no additional conditions beyond receiving such a payload are required for exploitation.

Generated by OpenCVE AI on July 24, 2026 at 09:37 UTC.

Remediation

Vendor Solution

Upgrade to Mojolicious 9.47 or later.


Vendor Workaround

Where upgrading is not possible, install Cpanel::JSON::XS in the include path and leave `MOJO_NO_JSON_XS` unset.


OpenCVE Recommended Actions

  • Upgrade the Mojolicious framework to version 9.47 or later, which replaces the unsafe pure‑Perl decoder with a depth‑checked implementation.
  • If an upgrade is not immediately possible, install the Cpanel::JSON::XS module in the Perl include path and ensure that MOJO_NO_JSON_XS is unset so that the fast JSON XS decoder is used in place of the vulnerable pure‑Perl path.
  • Add application or web‑server level checks that reject or limit excessively deep or large JSON payloads before they are parsed by Mojolicious—for example, enforce a maximum request body size or validate the parsed JSON for depth thresholds to prevent exhaustion attacks.

Generated by OpenCVE AI on July 24, 2026 at 09:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Sri
Sri mojo::json
Vendors & Products Sri
Sri mojo::json

Mon, 06 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Description Mojo::JSON versions before 9.47 for Perl allow memory exhaustion via unbounded recursion in the pure-Perl decoder. The pure-Perl decode path (`_decode_value` dispatching to `_decode_array` and `_decode_object`) recurses with no depth limit, so a small deeply nested JSON document can consume excessive memory. This path is the default when Cpanel::JSON::XS is not installed or `MOJO_NO_JSON_XS=1` is set; the Cpanel::JSON::XS fast path is not affected. Any caller that decodes an untrusted JSON body, for example `Mojo::Message::json` reached through `$c->req->json`, can exhaust process memory and cause denial of service.
Title Mojo::JSON versions before 9.47 for Perl allow memory exhaustion via unbounded recursion in the pure-Perl decoder
Weaknesses CWE-674
References

cve-icon MITRE

Status: PUBLISHED

Assigner: CPANSec

Published:

Updated: 2026-07-06T18:51:14.358Z

Reserved: 2026-07-05T21:23:29.979Z

Link: CVE-2026-14803

cve-icon Vulnrichment

Updated: 2026-07-06T05:27:01.702Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-24T09:45:02Z

Weaknesses