No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
No reference.
Mon, 21 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-400 CWE-674 |
|
| References |
|
|
| Metrics |
cvssV4_0
|
Mon, 21 Sep 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mojolicious is a real-time web framework for Perl. Prior to 9.47, the pure-Perl implementation of Mojo::JSON does not limit nesting depth when Cpanel::JSON::XS is unavailable or MOJO_NO_JSON_XS is enabled. An attacker who can supply untrusted JSON to decode_json, from_json, or j can submit deeply nested arrays or objects, causing unbounded recursion, memory exhaustion, and a process crash. Applications using the Cpanel::JSON::XS backend are not affected because that backend already enforces a nesting limit. This issue is fixed in version 9.47. | ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-14803. Reason: This candidate is a duplicate of CVE-2026-14803. Notes: All CVE users should reference CVE-2026-14803 instead of this candidate. |
| Title | Mojolicious pure-Perl Mojo::JSON decoder allows memory exhaustion via deeply nested data | |
| Metrics |
cvssV4_0
|
cvssV4_0
|
Sat, 19 Sep 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mojolicious
Mojolicious mojolicious |
|
| Vendors & Products |
Mojolicious
Mojolicious mojolicious |
Fri, 18 Sep 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mojolicious is a real-time web framework for Perl. Prior to 9.47, the pure-Perl implementation of Mojo::JSON does not limit nesting depth when Cpanel::JSON::XS is unavailable or MOJO_NO_JSON_XS is enabled. An attacker who can supply untrusted JSON to decode_json, from_json, or j can submit deeply nested arrays or objects, causing unbounded recursion, memory exhaustion, and a process crash. Applications using the Cpanel::JSON::XS backend are not affected because that backend already enforces a nesting limit. This issue is fixed in version 9.47. | |
| Title | Mojolicious pure-Perl Mojo::JSON decoder allows memory exhaustion via deeply nested data | |
| Weaknesses | CWE-400 CWE-674 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: REJECTED
Assigner: GitHub_M
Published:
Updated: 2026-09-21T17:52:24.272Z
Reserved: 2026-07-31T21:04:04.040Z
Link: CVE-2026-68914
No data.
Status : Rejected
Published: 2026-09-18T16:17:08.897
Modified: 2026-09-21T18:17:10.110
Link: CVE-2026-68914
No data.
OpenCVE Enrichment
Updated: 2026-09-19T22:15:05Z
No weakness.