Critical severity9.1NVD Advisory· Published Jul 14, 2026· Updated Jul 15, 2026
CVE-2026-15747
CVE-2026-15747
Description
Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH compression oracle.
_csrf_token generates and caches one token per session and returns the same value on every call, and _csrf_field places that value in a hidden csrf_token input. When a response carrying the token also echoes attacker-controlled input and is gzip-compressed, the chosen values and the resulting compressed lengths form a BREACH oracle.
An attacker able to query it can recover the token and pass csrf_protect validation.
Affected products
2- osv-coords2 versionspkg:rpm/opensuse/perl-Mojolicious&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/perl-Mojolicious&distro=openSUSE%20Tumbleweed
< 9.480.0-bp160.1.1+ 1 more
- (no CPE)range: < 9.480.0-bp160.1.1
- (no CPE)range: < 9.480.0-1.1
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.