CVE-2025-40929: Rurban Cpanel::json::xs

Medium severity, CVSS 5.6. EPSS: 0.4% chance of exploitation in the next 30 days.

Cpanel::JSON::XS before version 4.40 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified impact

Affected products

  • Rurban Cpanel::json::xs: before 4.40 (fixed in 4.40)

Published 2025-09-08. Last modified 2026-06-17.