Skip to content
Fedora 43 and 44 Address Critical CSRF Vulnerability in Perl-Mojolicious

Fedora 43 and 44 Address Critical CSRF Vulnerability in Perl-Mojolicious

First seen 28 Jul 2026, 10:02 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster July 29, 2026 at 05:12 UTC

Fedora has released updates for Perl-Mojolicious to address a critical CSRF vulnerability identified as CVE-2026-15747. The flaw, which was published on July 14, 2026, allowed for potential information disclosure via BREACH compression attacks. The vulnerability affects users of Mojolicious 9.48, where CSRF tokens were improperly reused across sessions. The update masks tokens with a fresh random value on each request, significantly enhancing security. Users are encouraged to apply the updates using the 'dnf' package manager. The updates were confirmed by Emmanuel Seyman on July 14, 2026. No active exploitation has been reported as of the latest advisories.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 45d ago How this analysis works

Timeline

2026-07-14
CVE-2026-15747 published
A critical CSRF vulnerability in Perl-Mojolicious was disclosed, allowing potential information disclosure.
Linuxsecurity
2026-07-14
Update to Mojolicious 9.48 released
Fedora released an update to Mojolicious 9.48 to fix the CSRF vulnerability by masking tokens with random values.
Linuxsecurity
2026-07-28
Advisory published for Fedora 44
Fedora 44 also released an advisory regarding the same critical CSRF vulnerability, urging users to update.
Linuxsecurity

More articles in this cluster (2)

Following this threat?

Track Fedora and CVE-2026-15747 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed