https://seclists.org/oss-sec/2025/q3/155: CVE-2025-40928: JSON::XS befoversion 4.04 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified
Published Sep 8, 2025
·Updated
Affected Software
1 affected component
CPAN JSON-XS<4.04
Frequently Asked Questions
1
What is the severity of CVE-2025-40928?
CVE-2025-40928 is classified as a high severity vulnerability due to its potential to cause denial-of-service attacks.
2
How do I fix CVE-2025-40928?
To fix CVE-2025-40928, you should upgrade JSON::XS to version 4.04 or higher.
3
What kind of attack does CVE-2025-40928 enable?
CVE-2025-40928 enables denial-of-service attacks due to an integer buffer overflow.
4
Which versions of JSON-XS are affected by CVE-2025-40928?
CVE-2025-40928 affects JSON::XS versions prior to 4.04.
5
Is there any workaround for CVE-2025-40928?
There are no effective workarounds for CVE-2025-40928 other than upgrading to a secure version.