Junglewise Threat Intelligence

CVE-2026-14803: Mojo::JSON memory exhaustion via unbounded recursion in decoder

CVE-2026-14803 · Severity: info · CVSS 5.3 · Published 2026-07-06

Executive brief

Mojo::JSON, a component of the Mojolicious web framework for Perl, is vulnerable to a denial-of-service attack. An attacker can send a specially crafted, deeply nested JSON document that causes the application to consume excessive memory and potentially crash. This affects applications that process untrusted JSON data when certain high-performance C libraries are not installed.

Technical details

A vulnerability exists in the pure-Perl implementation of Mojo::JSON's decoder where the `_decode_value`, `_decode_array`, and `_decode_object` functions recurse without a depth limit. An attacker can exploit this by submitting a small but deeply nested JSON document (e.g., thousands of opening brackets), leading to uncontrolled recursion and process memory exhaustion (Denial of Service). This issue specifically affects environments where `Cpanel::JSON::XS` is not installed or where `MOJO_NO_JSON_XS=1` is explicitly set. The vulnerability is resolved in version 9.47 by introducing a maximum nesting limit of 512 levels.

Affected products

  • SRI Mojo::JSON < 9.47

Timeline

  • 2026-07-05: patched: Fixed in version 9.47
  • 2026-07-06: advisory: NVD publication date

References