VYPR

Mojo

by Mojolicious

Source repositories

CVEs (5)

  • CVE-2026-15747CriJul 14, 2026
    risk 0.52cvss 9.1epss 0.00

    Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH compression oracle. _csrf_token generates and caches one token per session and returns the same value on every call, and _csrf_field places that value in a…

  • CVE-2020-36829HigApr 8, 2024
    risk 0.42cvss 7.5epss 0.01

    The Mojolicious module before 8.65 for Perl is vulnerable to secure_compare timing attacks that allow an attacker to guess the length of a secret string. Only versions after 1.74 are affected.

  • CVE-2018-25100MedMar 24, 2024
    risk 0.27cvss 5.3epss 0.01

    The Mojolicious module before 7.66 for Perl may leak cookies in certain situations related to multiple similar cookies for the same domain. This affects Mojo::UserAgent::CookieJar.

  • CVE-2024-58134HigMay 3, 2025
    risk 0.00cvss 8.1epss 0.01

    Mojolicious versions from 0.999922 for Perl uses a hard coded string, or the application's class name, as an HMAC session cookie secret by default. These predictable default secrets can be exploited by an attacker to forge session cookies.  An attacker who knows or guesses the…

  • CVE-2021-47208MedApr 8, 2024
    risk 0.00cvss 4.3epss 0.01

    The Mojolicious module before 9.11 for Perl has a bug in format detection that can potentially be exploited for denial of service.