Back Linuxsecurity Fedora 43 Perl-Mojolicious Important CSRF Token Fix FEDORA-2026
Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges ×
Back in the early days of the web there was this wonderful Perl library
called CGI, many people only learned Perl because of it. It was simple
enough to get started without knowing much the language and powerful
enough to keep you going, learning by doing was much fun. While most of the
techniques used are outdated now, the idea behind it is not. Mojolicious is
a new attempt at implementing this idea using state of the art technology.
Mojolicious 9.48 fixes a security issue where CSRF tokens were vulnerable to BREACH attacks. Tokens are now masked with a fresh random value on every request, instead of being reused for the whole lifetime of a session.
* Tue Jul 14 2026 Emmanuel Seyman - 9.48-1 - Update to 9.48
* Tue Jul 14 2026 Emmanuel Seyman - 9.48-1 - Update to 9.48
[ 1 ] Bug #2500953 - CVE-2026-15747 perl-Mojolicious: Mojolicious: Information disclosure via BREACH compression oracle [fedora-all]
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-6f12b08313' at the command line. For more information, refer to the dnf documentation available at
Get the latest Linux and open source security news straight to your inbox.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
