CVE-2022-48623: Rurban Cpanel::json::xs

Critical severity, CVSS 9.1. EPSS: 0.8% chance of exploitation in the next 30 days.

The Cpanel::JSON::XS package before 4.33 for Perl performs out-of-bounds accesses in a way that allows attackers to obtain sensitive information or cause a denial of service.

Affected products

  • Rurban Cpanel::json::xs: before 4.33 (fixed in 4.33)

Published 2024-02-13. Last modified 2026-06-17.