{"id":"AZL-92394","summary":"CVE-2026-15747 affecting package perl-Mojolicious 8.57-3","details":"Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH compression oracle.\n\n_csrf_token generates and caches one token per session and returns the same value on every call, and _csrf_field places that value in a hidden `csrf_token` input. When a response carrying the token also echoes attacker-controlled input and is gzip-compressed, the chosen values and the resulting compressed lengths form a BREACH oracle.\n\nAn attacker able to query it can recover the token and pass csrf_protect validation.","modified":"2026-09-09T05:27:39Z","published":"2026-07-14T18:17:12Z","upstream":["CVE-2026-15747"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-15747"}],"affected":[{"package":{"name":"perl-Mojolicious","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/perl-Mojolicious"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"8.57-3"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-92394.json"}}],"schema_version":"1.9.0"}