« Volver al listado

CVE-2026-9516

Estado: AnalizadaAlta (7.5)—

Cpanel::JSON::XS versions before 4.41 for Perl allow denial of service via UTF-8 BOM prefixed input when a decode filter callback throws.

To skip a leading 3-byte UTF-8 BOM, decode_json() advances the input scalar's string pointer past the mark with SvPV_set() and restores it only on the normal return path. When decoding aborts through a Perl exception, for example a filter_json_object callback that croaks, the restore is skipped and the scalar is left with its string pointer offset into its own buffer and a shortened length.

When that scalar is later freed, the allocator receives an invalid pointer and the interpreter aborts. A single BOM prefixed document decoded with a throwing filter callback crashes any caller.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad de DoS remota en librería Perl accesible sin autenticación (AV:N, PR:N, UI:N). Entrada UTF-8 malformada causa crash del intérprete. CWE-755 (excepción no manejada).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-9516",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-9516",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-06-03T15:58:42.977647Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "9b29abf9-4ab0-4765-b253-1875cd9b441e",
      "affectedData": [
        {
          "repo": "https://github.com/rurban/Cpanel-JSON-XS",
          "vendor": "RURBAN",
          "product": "Cpanel::JSON::XS",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "4.41",
              "versionType": "custom"
            }
          ],
          "packageName": "Cpanel-JSON-XS",
          "programFiles": [
            "XS.xs"
          ],
          "collectionURL": "https://cpan.org/modules",
          "defaultStatus": "unaffected",
          "programRoutines": [
            {
              "name": "decode_json"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-06-03T01:16:23.430",
  "references": [
    {
      "url": "https://github.com/rurban/Cpanel-JSON-XS/commit/dfe1b41a36caba51dc12a2917fe50285d1ffaa7b.patch",
      "tags": [
        "Patch"
      ],
      "source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
    },
    {
      "url": "https://metacpan.org/release/RURBAN/Cpanel-JSON-XS-4.41/changes",
      "tags": [
        "Release Notes"
      ],
      "source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2026/06/03/5",
      "tags": [
        "Mailing List",
        "Patch",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "9b29abf9-4ab0-4765-b253-1875cd9b441e",
      "description": [
        {
          "lang": "en",
          "value": "CWE-755"
        },
        {
          "lang": "en",
          "value": "CWE-763"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Cpanel::JSON::XS versions before 4.41 for Perl allow denial of service via UTF-8 BOM prefixed input when a decode filter callback throws.\n\nTo skip a leading 3-byte UTF-8 BOM, decode_json() advances the input scalar's string pointer past the mark with SvPV_set() and restores it only on the normal return path. When decoding aborts through a Perl exception, for example a filter_json_object callback that croaks, the restore is skipped and the scalar is left with its string pointer offset into its own buffer and a shortened length.\n\nWhen that scalar is later freed, the allocator receives an invalid pointer and the interpreter aborts. A single BOM prefixed document decoded with a throwing filter callback crashes any caller."
    },
    {
      "lang": "es",
      "value": "Las versiones de Cpanel::JSON::XS anteriores a la 4.41 para Perl permiten la denegación de servicio a través de una entrada prefijada con BOM UTF-8 cuando una devolución de llamada de filtro de decodificación lanza una excepción.\n\nPara omitir un BOM UTF-8 inicial de 3 bytes, decode_json() avanza el puntero de cadena del escalar de entrada más allá de la marca con SvPV_set() y lo restaura solo en la ruta de retorno normal. Cuando la decodificación se aborta a través de una excepción de Perl, por ejemplo, una devolución de llamada filter_json_object que falla, la restauración se omite y el escalar queda con su puntero de cadena desplazado dentro de su propio búfer y una longitud acortada.\n\nCuando ese escalar se libera posteriormente, el asignador recibe un puntero no válido y el intérprete se aborta. Un único documento prefijado con BOM decodificado con una devolución de llamada de filtro que lanza una excepción bloquea a cualquier llamador."
    }
  ],
  "lastModified": "2026-07-22T19:10:00.120",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:rurban:cpanel\\:\\:json\\:\\:xs:*:*:*:*:*:perl:*:*",
              "vulnerable": true,
              "matchCriteriaId": "41C09D6F-C2F2-42BF-9734-B6F7D9E02777",
              "versionEndExcluding": "4.41"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
}