Junglewise Threat Intelligence

CVE-2026-9334: Cpanel::JSON::XS type confusion via duplicate object keys

CVE-2026-9334 · Severity: info · CVSS 0 · Published 2026-06-03

Vendors: cPanel.

Executive brief

Cpanel::JSON::XS is a high-performance Perl library used for converting data between Perl and JSON formats. A flaw in how it handles duplicate keys in JSON data can cause the application to crash or potentially allow an attacker to manipulate memory. This could lead to a denial-of-service or further security compromises if an application processes untrusted JSON input from the internet.

Technical details

A type confusion vulnerability exists in the decode_hv() function of Cpanel::JSON::XS when the 'dupkeys_as_arrayref' option is enabled. The vulnerability is caused by a logic error where the code attempts to dereference a scalar value (SvRV) before verifying it is actually a reference. Specifically, a conditional check used '&&' instead of '||', allowing the code to proceed with an incompatible access if a second distinct key in a JSON object also contains duplicates. An attacker providing specially crafted JSON with duplicate keys can trigger a segmentation fault (DoS) or potentially achieve arbitrary memory access by controlling the pointer taken from the scalar contents. This affects both the fast and slow parsing paths in XS.xs.

Affected products

  • Cpanel Cpanel::JSON::XS before 4.41

Timeline

  • 2026-05-26: other: Vulnerability identified and patch authored by Paul Johnson
  • 2026-05-27: patched: Fixed in version 4.41
  • 2026-06-03: disclosed: CVE-2026-9334 published

References

Related threats