Vulnerability Description
Cpanel::JSON::XS versions before 4.41 for Perl allow type confusion via duplicate object keys when dupkeys_as_arrayref is enabled. decode_hv() collapses duplicate object keys into an array reference under dupkeys_as_arrayref. The branch reached for a duplicate key tests `SvTYPE (old_value) != SVt_RV && SvTYPE (SvRV (old_value)) != SVt_PVAV`, which evaluates SvRV(old_value) before establishing that old_value is a reference. When the existing value is a plain scalar rather than an array reference, a non-reference scalar is dereferenced as a reference. A caller decoding untrusted JSON with dupkeys_as_arrayref enabled is crashed, and the incompatible access follows a pointer taken from attacker controlled scalar contents.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rurban | Cpanel\ | < 4.41, \ |
Related Weaknesses (CWE)
References
- https://github.com/rurban/Cpanel-JSON-XS/commit/11a7c550a0d8fac2f84414f24d5df9b2Patch
- https://metacpan.org/release/RURBAN/Cpanel-JSON-XS-4.41/changesRelease Notes
- http://www.openwall.com/lists/oss-security/2026/06/03/4Mailing ListPatchThird Party Advisory
FAQ
What is CVE-2026-9334?
CVE-2026-9334 is a vulnerability with a CVSS score of 7.3 (HIGH). Cpanel::JSON::XS versions before 4.41 for Perl allow type confusion via duplicate object keys when dupkeys_as_arrayref is enabled. decode_hv() collapses duplicate object keys into an array reference ...
How severe is CVE-2026-9334?
CVE-2026-9334 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-9334?
Check the references section above for vendor advisories and patch information. Affected products include: Rurban Cpanel\.