CVE-2025-40929: Cpanel::JSON::XS before version 4.40 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified impact
Published Sep 8, 2025
·Updated
Cpanel::JSON::XS before version 4.40 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified impact
Affected Software
1 affected component
Cpanel JSON::XS<4.40
Remediation
Information
Update to 4.40 or later, or apply the provided patch
Event History
Sep 8, 2025
CVE Published
via MITRE·03:08 PM
Data Sourced
via MITRE·03:08 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-40929?
CVE-2025-40929 is considered a high severity vulnerability due to its potential to cause a denial-of-service attack.
2
How do I fix CVE-2025-40929?
To fix CVE-2025-40929, upgrade Cpanel::JSON::XS to version 4.40 or later.
3
What impact does CVE-2025-40929 have on applications?
CVE-2025-40929 can result in a segmentation fault when parsing crafted JSON, leading to application crashes.
4
Which versions of Cpanel::JSON::XS are affected by CVE-2025-40929?
CVE-2025-40929 affects all versions of Cpanel::JSON::XS prior to 4.40.
5
What type of attacks can CVE-2025-40929 facilitate?
CVE-2025-40929 can facilitate denial-of-service attacks by causing applications to crash.