VYPR

Mojo::JSON

by Mojolicious

CVEs (1)

  • CVE-2026-68914HigSep 18, 2026
    risk 0.50cvss epss

    Mojolicious is a real-time web framework for Perl. Prior to 9.47, the pure-Perl implementation of Mojo::JSON does not limit nesting depth when Cpanel::JSON::XS is unavailable or MOJO_NO_JSON_XS is enabled. An attacker who can supply untrusted JSON to decode_json, from_json, or j…