{"id":"openSUSE-SU-2026:21140-1","summary":"Security update for perl-Cpanel-JSON-XS","details":"This update for perl-Cpanel-JSON-XS fixes the following issues:\n\nChanges in perl-Cpanel-JSON-XS:\n\n- updated to 4.420.0 (4.42)\n   see /usr/share/doc/packages/perl-Cpanel-JSON-XS/Changes\n\n  4.42 2026-06-27 (rurban)\n\t- Ensure encode with a type spec hashref does not change the hashref argument (GH #240)\n          - Fix -e docs: \"written\" → \"read\" (GH #239, reported by Ron Savage).\n          - Fix Boolean eq overload matching undef (GH #207, reported by fd-t).\n            Cpanel::JSON::XS::Boolean overloaded eq would match undef as equal\n            to false because undef stringifies to \"\". Added defined() guard.\n          - Fix error messages showing overloaded stringification for blessed\n            objects (GH #191, reported by karenetheridge). Error messages now\n            use ClassName=TYPE(addr) format, bypassing any \"\" overload.\n          - Fix type_all_string overriding allow_blessed/convert_blessed (GH #175,\n            reported by alpha6). With type_all_string + allow_blessed, blessed\n            objects are now encoded as null (not stringified as HASH address).\n          - Fix infinite recursion when encode is called from a \"\" overload\n            (GH #128, reported by pbrthemaster). The recursion guard temporarily\n            clears convert_blessed and allow_stringify flags on the JSON object\n            before calling the overload, preventing re-entrant encode loops.\n          - Fix $obj-\u003enew creating a broken object (GH #93, reported by cpansprout).\n            When new() is called on an existing object (e.g. $json-\u003enew-\u003enew),\n            the class name is now extracted from the object's stash rather than\n            using the stringified reference.\n          - Change allow_nonref default to true (GH #241, matching JSON::PP and\n            JSON::XS 4.0+ and the insecure RFC 7159).\n            encode and decode now accept non-reference values by default.\n            decode_json() with an explicit 0/1 second argument still works.\n            allow_nonref(0) to disable scalars-only for secure JSON.\n          - Fix minor t/12_blessed.t typo.\n          - Fix GH #112: encode large whole-number NV values without .0 on\n            32-bit Perl (values exceeding UV_MAX that Perl stores as float).\n          - Fix GH #197: prefer IOK over pNOK when encoding values where\n            IV is accurate but NV is imprecise (SvNOK not set).\n\n- updated to 4.410.0 (4.41)\n   see /usr/share/doc/packages/perl-Cpanel-JSON-XS/Changes\n\n  4.41 2026-05-27 (rurban)\n  - Fix BOM-shift PV-corruption SIGABRT (CVE-2026-9516) (patch by Paul Johnson) bsc#1267547\n  - Fix dupkeys_as_arrayref type confusion (CVE-2026-9334) (patch by Paul Johnson) bsc#1267546\n  - Fix incr_parse single-quote string delimiter (GH #245, reported by\n    Paul Johnson)\n  - Fix a one-byte out-of-bounds heap read reachable via allow_barekey on\n    truncated input (GH #244, reported by Paul Johnson)\n\n- updated to 4.400.0 (4.40)\n   see /usr/share/doc/packages/perl-Cpanel-JSON-XS/Changes\n\n  4.40 2025-09-07 (rurban)\n  - Fix CVE-2025-40929 overflow with overlong numbers, fuzzing only.\n  - Detect more malformed numbers, with two decimal points.\n  - Pin github actions to latest @v via pinact run -u\n  (bsc#1249331)\n\n- updated to 4.390.0 (4.39)\n   see /usr/share/doc/packages/perl-Cpanel-JSON-XS/Changes\n\n  4.39 2024-12-12 (rurban)\n          - Fix Windows -Dusequadmath (sisyphus GH #235, GH #229)\n          - Fix inconsistent behavior between decoding escaped and unescaped\n            surrogates, and escaped non-characters vs non-escaped non-characters.\n            Now aligned to JSON::PP (Gavin Hayes GH #233, GH #227)\n          - Add type_all_string tests (Bernhard Schmalhofer GH #236)\n          - Silence UV to char cast warnings  (bulk88 GH #232)\n          - Fix MSVC preprocessor errors (bulk88 GH #232)\n          - Fix -Wformat warnings on Windows (sisyphus GH #228)\n          - Clarify BigInt decoding (GH #226)\n","modified":"2026-06-30T18:24:44.871871683Z","published":"2026-06-19T09:45:15Z","related":["CVE-2025-40929","CVE-2026-9334","CVE-2026-9516"],"upstream":["CVE-2025-40929","CVE-2026-9334","CVE-2026-9516"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1249331"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267546"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267547"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-40929"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-9334"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-9516"}],"affected":[{"package":{"name":"perl-Cpanel-JSON-XS","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/perl-Cpanel-JSON-XS&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.420.0-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"perl-Cpanel-JSON-XS":"4.420.0-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21140-1.json"}}],"schema_version":"1.7.5"}