Integer Buffer Overflow Vulnerability in Cpanel::JSON::XS for Perl
CVE-2025-40929

5.6MEDIUM

Key Information:

Vendor

Rurban

Vendor
CVE Published:
8 September 2025

What is CVE-2025-40929?

An integer buffer overflow vulnerability has been identified in Cpanel::JSON::XS prior to version 4.40 for Perl. This issue occurs during the parsing of specifically crafted JSON data, potentially leading to a segmentation fault. The vulnerability can be exploited to launch denial-of-service attacks, impacting the availability of the affected applications and services. Users are advised to update to the latest version to mitigate this risk and ensure system integrity.

Affected Version(s)

Cpanel::JSON::XS 0 < 4.40

References

CVSS V3.1

Score:
5.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael Hudak of rasotec
.
CVE-2025-40929 : Integer Buffer Overflow Vulnerability in Cpanel::JSON::XS for Perl