Linuxsecurity Fedora Releases Security Updates for Mojo::JWT to Mitigate Timing Attacks
Article Content
- •Fedora has released critical updates for the perl-Mojo-JWT package to address timing attack vulnerabilities.
- •The updates affect users of Fedora versions 43 and 44, specifically targeting the decode function.
- •Users are urged to apply the updates promptly to prevent potential exploitation of these vulnerabilities.
On June 7, 2026, Fedora released updates for the perl-Mojo-JWT package in versions 43 and 44 to address vulnerabilities related to timing side-channel attacks in symmetric signatures. These updates improve the security of the decode function, which is crucial for applications using JSON Web Tokens (JWT). The updates were published under Fedora Update Notifications FEDORA-2026-1da54e6cb8 and FEDORA-2026-80333f8f56. Users of Fedora 43 and 44 are advised to apply these updates promptly to mitigate potential exploitation risks. The vulnerabilities could allow attackers to glean sensitive information through timing analysis, impacting applications that rely on JWT for authentication and authorization. The updates can be installed using the 'dnf' update program. The advisory was issued by Emmanuel Seyman, who is responsible for maintaining the package.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Fedora in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…