Skip to content
Critical DoS Vulnerabilities in perl-Cpanel-JSON-XS Affect Fedora Users

Critical DoS Vulnerabilities in perl-Cpanel-JSON-XS Affect Fedora Users

First seen 5 Jun 2026, 12:10 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 6, 2026 at 11:53 UTC
  • Fedora updates address critical DoS vulnerabilities in perl-Cpanel-JSON-XS.
  • CVE-2026-9516 and CVE-2026-9334 can lead to application crashes via malformed JSON.
  • Users are urged to apply the updates immediately using the 'dnf' package manager.

Fedora has released updates for the perl-Cpanel-JSON-XS package addressing critical Denial of Service (DoS) vulnerabilities identified as CVE-2026-9516 and CVE-2026-9334. These vulnerabilities can be exploited through malformed JSON input, leading to application crashes. The issues were published on June 3, 2026, and affect users of Fedora 43 and 44. The updates fix a BOM-shift PV-corruption SIGABRT and a type confusion with duplicate JSON object keys. Users are advised to apply the updates using the 'dnf' package manager. The vulnerabilities were confirmed by Fedora Release Engineering and are considered significant due to their potential impact on system stability. The updates were made available on May 28, 2026.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 97d ago How this analysis works

Timeline

2026-05-28
Fedora updates released
Updates for perl-Cpanel-JSON-XS addressing critical DoS vulnerabilities were released by Paul Howarth.
Linuxsecurity
2026-06-03
CVE-2026-9334 published
Denial of Service via type confusion with duplicate JSON object keys reported for perl-Cpanel-JSON-XS.
Linuxsecurity
2026-06-03
CVE-2026-9516 published
Denial of Service via UTF-8 BOM prefixed input reported for perl-Cpanel-JSON-XS.
Linuxsecurity

More articles in this cluster (2)

Following this threat?

Track CVE-2026-9334 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed