Medium severity6.5NVD Advisory· Published Jul 6, 2026· Updated Jul 6, 2026
CVE-2026-14803
CVE-2026-14803
Description
Mojo::JSON versions before 9.47 for Perl allow memory exhaustion via unbounded recursion in the pure-Perl decoder.
The pure-Perl decode path (_decode_value dispatching to _decode_array and _decode_object) recurses with no depth limit, so a small deeply nested JSON document can consume excessive memory.
This path is the default when Cpanel::JSON::XS is not installed or MOJO_NO_JSON_XS=1 is set; the Cpanel::JSON::XS fast path is not affected.
Any caller that decodes an untrusted JSON body, for example Mojo::Message::json reached through $c->req->json, can exhaust process memory and cause denial of service.
Affected products
2- Range: <9.47
- Range: <9.47
Patches
Vulnerability mechanics
References
3News mentions
1- Perl Modules: Seven Vulnerabilities Disclosed, Affecting DBI, Crypt::DSA, and MoreVypr Intelligence · Jul 8, 2026