Fedora Releases Security Updates for Mojo::JWT to Mitigate Timing Attacks

Fedora Releases Security Updates for Mojo::JWT to Mitigate Timing Attacks

First seen 16 Jun 2026, 03:20 UTC Linuxsecurity 98% similarity 57.8

Article Content

Browse articles
ThreatCluster

On June 7, 2026, Fedora released updates for the perl-Mojo-JWT package in versions 43 and 44 to address vulnerabilities related to timing side-channel attacks in symmetric signatures. These updates improve the security of the decode function, which is crucial for applications using JSON Web Tokens (JWT). The updates were published under Fedora Update Notifications FEDORA-2026-1da54e6cb8 and FEDORA-2026-80333f8f56. Users of Fedora 43 and 44 are advised to apply these updates promptly to mitigate potential exploitation risks. The vulnerabilities could allow attackers to glean sensitive information through timing analysis, impacting applications that rely on JWT for authentication and authorization. The updates can be installed using the 'dnf' update program. The advisory was issued by Emmanuel Seyman, who is responsible for maintaining the package.

Key Points: • Fedora has released critical updates for the perl-Mojo-JWT package to address timing attack vulnerabilities. • The updates affect users of Fedora versions 43 and 44, specifically targeting the decode function. • Users are urged to apply the updates promptly to prevent potential exploitation of these vulnerabilities.

ThreatCluster AI How this analysis works

Timeline

2026-06-07
Updates released for perl-Mojo-JWT
Fedora released security updates for the perl-Mojo-JWT package to mitigate timing side-channel attacks.
Linuxsecurity
2026-06-16
Fedora 44 security advisory published
Fedora issued an advisory for perl-Mojo-JWT in version 44, addressing the same vulnerabilities as in version 43.
Linuxsecurity

Community

Browse all →

Tracked Entities in This Story