Critical DoS Vulnerabilities in perl-Cpanel-JSON-XS Affect Fedora Users

Critical DoS Vulnerabilities in perl-Cpanel-JSON-XS Affect Fedora Users

First seen 5 Jun 2026, 12:10 UTC Linuxsecurity 95% similarity 70.5

Article Content

Browse articles
ThreatCluster

Fedora has released updates for the perl-Cpanel-JSON-XS package addressing critical Denial of Service (DoS) vulnerabilities identified as CVE-2026-9516 and CVE-2026-9334. These vulnerabilities can be exploited through malformed JSON input, leading to application crashes. The issues were published on June 3, 2026, and affect users of Fedora 43 and 44. The updates fix a BOM-shift PV-corruption SIGABRT and a type confusion with duplicate JSON object keys. Users are advised to apply the updates using the 'dnf' package manager. The vulnerabilities were confirmed by Fedora Release Engineering and are considered significant due to their potential impact on system stability. The updates were made available on May 28, 2026.

Key Points: • Fedora updates address critical DoS vulnerabilities in perl-Cpanel-JSON-XS. • CVE-2026-9516 and CVE-2026-9334 can lead to application crashes via malformed JSON. • Users are urged to apply the updates immediately using the 'dnf' package manager.

ThreatCluster AI

Timeline

2026-05-28
Fedora updates released
Updates for perl-Cpanel-JSON-XS addressing critical DoS vulnerabilities were released by Paul Howarth.
Linuxsecurity
2026-06-03
CVE-2026-9334 published
Denial of Service via type confusion with duplicate JSON object keys reported for perl-Cpanel-JSON-XS.
Linuxsecurity
2026-06-03
CVE-2026-9516 published
Denial of Service via UTF-8 BOM prefixed input reported for perl-Cpanel-JSON-XS.
Linuxsecurity

Community

Browse all →

Tracked Entities in This Story