Linuxsecurity Fedora 43 and 44 Address Critical CSRF Vulnerability in Perl-Mojolicious
Article Content
- •CVE-2026-15747 addresses a critical CSRF vulnerability in Perl-Mojolicious.
- •Tokens were previously reused, making them vulnerable to BREACH attacks.
- •Users are advised to upgrade to Mojolicious 9.48 to mitigate risks.
Fedora has released updates for Perl-Mojolicious to address a critical CSRF vulnerability identified as CVE-2026-15747. The flaw, which was published on July 14, 2026, allowed for potential information disclosure via BREACH compression attacks. The vulnerability affects users of Mojolicious 9.48, where CSRF tokens were improperly reused across sessions. The update masks tokens with a fresh random value on each request, significantly enhancing security. Users are encouraged to apply the updates using the 'dnf' package manager. The updates were confirmed by Emmanuel Seyman on July 14, 2026. No active exploitation has been reported as of the latest advisories.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Fedora and CVE-2026-15747 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…