Rurban's vulnerability profile centers on cPanel, a widely deployed web hosting control panel, with the durable signal reflecting memory-handling and error-processing weaknesses such as type confusion, out-of-bounds reads, and improper exception handling. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rurban over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-9516HIGH Cpanel::JSON::XS versions before 4.41 for Perl allow denial of service via UTF-8 BOM prefixed input when a decode filter callback throws.
To skip a leading 3-byte UTF-8 BOM, decod | Jun 3, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-9334HIGH Cpanel::JSON::XS versions before 4.41 for Perl allow type confusion via duplicate object keys when dupkeys_as_arrayref is enabled.
decode_hv() collapses duplicate object keys into | Jun 3, 2026 | 7.3 | 32 | NO | NO |
CVE-2022-48623CRITICAL The Cpanel::JSON::XS package before 4.33 for Perl performs out-of-bounds accesses in a way that allows attackers to obtain sensitive information or cause a denial of service. | Feb 13, 2024 | 9.1 | 28 | NO | NO |
CVE-2025-40929MEDIUM Cpanel::JSON::XS before version 4.40 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified i | Sep 8, 2025 | 5.6 | 22 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rurban.
Media articles that mention a CVE ID that affects a product developed by Rurban — matched by CVE ID, not by vendor name.