CVE-2026-14803

Mojo::JSON versions before 9.47 for Perl allow memory exhaustion via unbounded recursion in the pure-Perl decoder. The pure-Perl decode path (`_decode_value` dispatching to `_decode_array` and `_decode_object`) recurses with no depth limit, so a small deeply nested JSON document can consume excessive memory. This path is the default when Cpanel::JSON::XS is not installed or `MOJO_NO_JSON_XS=1` is set; the Cpanel::JSON::XS fast path is not affected. Any caller that decodes an untrusted JSON body, for example `Mojo::Message::json` reached through `$c->req->json`, can exhaust process memory and cause denial of service.
Configurations

No configuration.

History

06 Jul 2026, 19:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

06 Jul 2026, 06:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2026/07/06/2 -

06 Jul 2026, 02:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-06 02:16

Updated : 2026-07-06 19:16


NVD link : CVE-2026-14803

Mitre link : CVE-2026-14803

CVE.ORG link : CVE-2026-14803


JSON object : View

Products Affected

No product.

CWE
CWE-674

Uncontrolled Recursion