Description
JSON::XS before version 4.04 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified impact
Problem types
CWE-122 Heap-based Buffer Overflow
Product status
Any version before 4.04
Credits
Michael Hudak of rasotec
References
metacpan.org/release/MLEHMANN/JSON-XS-4.03/source/XS.xs
security.metacpan.org/...SON-XS/4.03/CVE-2025-40928-r1.patch