Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-92394.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-92394
Upstream
Published
2026-07-14T18:17:12Z
Modified
2026-09-09T05:27:39Z
Summary
CVE-2026-15747 affecting package perl-Mojolicious 8.57-3
Details

Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH compression oracle.

_csrf_token generates and caches one token per session and returns the same value on every call, and _csrf_field places that value in a hidden csrf_token input. When a response carrying the token also echoes attacker-controlled input and is gzip-compressed, the chosen values and the resulting compressed lengths form a BREACH oracle.

An attacker able to query it can recover the token and pass csrf_protect validation.

References

Affected packages

Azure Linux:3 / perl-Mojolicious

Package

Name
perl-Mojolicious
Purl
pkg:rpm/azure-linux/perl-Mojolicious

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
8.57-3

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-92394.json"