CPANSA-Mojolicious-2026-77568: Mojolicious vulnerability

Publisher giterlizzi Document category csaf_security_advisory
Initial release date 2026-09-18T00:00:00 Engine CSAF Perl Toolkit 0.26
Current release date 2026-09-18T00:00:00 Build Date
Current version 1 Status final
CVSS v3.1 Base Score Severity Medium
Original language Language en
Also referred to

Vulnerability Description

Mojolicious is a real-time web framework for Perl. Prior to 9.48, the Mojolicious CSRF helpers csrf_field, csrf_token, and csrf_protect reuse an unchanged per-session token in rendered HTML. When response compression is enabled and attacker-influenced content is reflected in the same response, an unauthenticated attacker who can induce many victim requests and observe response sizes can use a BREACH compression side channel to recover the token and forge cross-site requests. API-only deployments that never render the token in HTML are not affected. This issue is fixed in version 9.48.

Vulnerabilities

CVE-2026-77568

Vulnerability Description

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-15747. Reason: This candidate is a duplicate of CVE-2026-15747. Notes: All CVE users should reference CVE-2026-15747 instead of this candidate.

Product status

Known affected
Product Score
Mojolicious less than 9.48
CVSS Version CVSS Vector CVSS Base Score CVSS Base Severity
Fixed

giterlizzi

Namespace: https://github.com/giterlizzi/

gdt@cpan.org

References

Revision history

Version Date of the revision Summary of the revision
1 Fri Sep 18 00:00:00 2026 First release

Sharing rules

TLP:WHITE
For the TLP version see: https://www.first.org/tlp/