Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 18 Sep 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mojolicious is a real-time web framework for Perl. Prior to 9.47, the pure-Perl implementation of Mojo::JSON does not limit nesting depth when Cpanel::JSON::XS is unavailable or MOJO_NO_JSON_XS is enabled. An attacker who can supply untrusted JSON to decode_json, from_json, or j can submit deeply nested arrays or objects, causing unbounded recursion, memory exhaustion, and a process crash. Applications using the Cpanel::JSON::XS backend are not affected because that backend already enforces a nesting limit. This issue is fixed in version 9.47. | |
| Title | Mojolicious pure-Perl Mojo::JSON decoder allows memory exhaustion via deeply nested data | |
| Weaknesses | CWE-400 CWE-674 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-18T16:07:27.117Z
Reserved: 2026-07-31T21:04:04.040Z
Link: CVE-2026-68914
No data.
Status : Received
Published: 2026-09-18T16:17:08.897
Modified: 2026-09-18T16:17:08.897
Link: CVE-2026-68914
No data.
OpenCVE Enrichment
No data.