ALPINE-CVE-2025-40929

Source
https://security.alpinelinux.org/vuln/CVE-2025-40929
Import Source
https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2025-40929.json
JSON Data
https://api.osv.dev/v1/vulns/ALPINE-CVE-2025-40929
Upstream
Published
2025-09-08T15:15:35.957Z
Modified
2025-12-03T23:00:04.338508Z
Severity
  • 5.6 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
Summary
[none]
Details

Cpanel::JSON::XS before version 4.40 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified impact

References

Affected packages

Alpine:v3.20 / perl-cpanel-json-xs

Package

Name
perl-cpanel-json-xs
Purl
pkg:apk/alpine/perl-cpanel-json-xs?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.40-r0

Affected versions

3.*
3.0115-r0
3.0115-r1
3.0217-r0
3.0218-r0
3.0219-r0
3.0220-r0
3.0223-r0
3.0224-r0
3.0225-r0
3.0226-r0
3.0227-r0
3.0228-r0
3.0230-r0
3.0231-r0
3.0232-r0
3.0233-r0
3.0233-r1
3.0237-r0
3.0238-r0
3.0239-r0
4.*
4.00-r0
4.01-r0
4.02-r0
4.03-r0
4.04-r0
4.05-r0
4.06-r0
4.08-r0
4.09-r0
4.11-r0
4.11-r1
4.12-r0
4.12-r1
4.13-r0
4.14-r0
4.15-r0
4.17-r0
4.18-r0
4.19-r0
4.21-r0
4.22-r0
4.23-r0
4.23-r1
4.24-r0
4.25-r0
4.26-r0
4.26-r1
4.27-r0
4.28-r0
4.29-r0
4.29-r1
4.30-r0
4.32-r0
4.34-r0
4.35-r0
4.36-r0
4.36-r1
4.36-r2
4.37-r0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2025-40929.json"

Alpine:v3.21 / perl-cpanel-json-xs

Package

Name
perl-cpanel-json-xs
Purl
pkg:apk/alpine/perl-cpanel-json-xs?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.40-r0

Affected versions

4.*
4.38-r0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2025-40929.json"

Alpine:v3.22 / perl-cpanel-json-xs

Package

Name
perl-cpanel-json-xs
Purl
pkg:apk/alpine/perl-cpanel-json-xs?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.40-r0

Affected versions

4.*
4.38-r0
4.39-r0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2025-40929.json"

Alpine:v3.23 / perl-cpanel-json-xs

Package

Name
perl-cpanel-json-xs
Purl
pkg:apk/alpine/perl-cpanel-json-xs?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.40-r0

Affected versions

4.*
4.38-r0
4.39-r0
4.39-r1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2025-40929.json"