PT-2025-36474 · Unknown+4 · Cpanel::Json::Xs+4

Michael Hudak

·

Published

2025-04-16

·

Updated

2025-11-13

·

CVE-2025-40929

CVSS v3.1

5.6

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions: Cpanel::JSON::XS versions prior to 4.40
Description: Cpanel::JSON::XS, a Perl module, contains an integer buffer overflow. This overflow occurs when parsing specially crafted JSON data, leading to a segmentation fault. This can result in denial-of-service attacks.
Recommendations: Update Cpanel::JSON::XS to version 4.40 or later.

Fix

DoS

RCE

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

AZL-67086
AZL-67088
BDU:2025-13817
CVE-2025-40929
DLA-4318-1
DSA-6000-1
MGASA-2025-0284
OESA-2025-2241
OESA-2025-2242
OPENSUSE-SU-2025:15534-1
SUSE-SU-2025:03193-1
USN-7749-1

Affected Products

Cpanel::Json::Xs
Debian
Linuxmint
Red Os
Ubuntu