No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
No reference.
Mon, 21 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-200 CWE-352 |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Mon, 21 Sep 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mojolicious is a real-time web framework for Perl. Prior to 9.48, the Mojolicious CSRF helpers csrf_field, csrf_token, and csrf_protect reuse an unchanged per-session token in rendered HTML. When response compression is enabled and attacker-influenced content is reflected in the same response, an unauthenticated attacker who can induce many victim requests and observe response sizes can use a BREACH compression side channel to recover the token and forge cross-site requests. API-only deployments that never render the token in HTML are not affected. This issue is fixed in version 9.48. | ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-15747. Reason: This candidate is a duplicate of CVE-2026-15747. Notes: All CVE users should reference CVE-2026-15747 instead of this candidate. |
Sat, 19 Sep 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mojolicious
Mojolicious mojolicious |
|
| Vendors & Products |
Mojolicious
Mojolicious mojolicious |
Fri, 18 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 18 Sep 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mojolicious is a real-time web framework for Perl. Prior to 9.48, the Mojolicious CSRF helpers csrf_field, csrf_token, and csrf_protect reuse an unchanged per-session token in rendered HTML. When response compression is enabled and attacker-influenced content is reflected in the same response, an unauthenticated attacker who can induce many victim requests and observe response sizes can use a BREACH compression side channel to recover the token and forge cross-site requests. API-only deployments that never render the token in HTML are not affected. This issue is fixed in version 9.48. | |
| Title | Mojolicious: CSRF tokens are vulnerable to BREACH attacks | |
| Weaknesses | CWE-200 CWE-352 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: REJECTED
Assigner: GitHub_M
Published:
Updated: 2026-09-21T17:51:20.075Z
Reserved: 2026-08-20T20:35:30.147Z
Link: CVE-2026-77568
Updated: 2026-09-18T17:24:16.551Z
Status : Rejected
Published: 2026-09-18T16:17:09.307
Modified: 2026-09-21T18:17:10.830
Link: CVE-2026-77568
No data.
OpenCVE Enrichment
Updated: 2026-09-19T22:15:05Z
No weakness.