Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-92078.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-92078
Upstream
Published
2026-07-06T02:16:21Z
Modified
2026-08-31T05:26:07Z
Summary
CVE-2026-14803 affecting package perl-Mojolicious 8.57-3
Details

Mojo::JSON versions before 9.47 for Perl allow memory exhaustion via unbounded recursion in the pure-Perl decoder.

The pure-Perl decode path (_decode_value dispatching to _decode_array and _decode_object) recurses with no depth limit, so a small deeply nested JSON document can consume excessive memory.

This path is the default when Cpanel::JSON::XS is not installed or MOJO_NO_JSON_XS=1 is set; the Cpanel::JSON::XS fast path is not affected.

Any caller that decodes an untrusted JSON body, for example Mojo::Message::json reached through $c->req->json, can exhaust process memory and cause denial of service.

References

Affected packages

Azure Linux:3 / perl-Mojolicious

Package

Name
perl-Mojolicious
Purl
pkg:rpm/azure-linux/perl-Mojolicious

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
8.57-3

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-92078.json"