{"id":"openSUSE-SU-2026:21451-1","summary":"Security update for perl-Mojolicious","details":"This update for perl-Mojolicious fixes the following issues:\n\nChanges in perl-Mojolicious:\n\n- updated to 9.480.0 (9.48)\n    - Fixed a security issue where CSRF tokens were vulnerable to BREACH attacks. Tokens are now masked with a fresh\n      random value on every request, instead of being reused for the whole lifetime of a session.\n      CVE-2026-15747 bsc#1271431\n\n- updated to 9.470.0 (9.47)\n    - Added support for the QUERY HTTP request method from RFC 10008.\n    - Added query and query_p methods to Mojo::UserAgent.\n    - Added query method to Mojolicious::Routes::Route.\n    - Added query method to Mojolicious::Lite.\n    - Added query_ok method to Test::Mojo.\n    - Fixed a security issue where the pure-Perl implementation of Mojo::JSON could exhaust all available memory when\n      decoding deeply nested data. Decoding is now limited to 512 levels of nesting, to match the default of\n      Cpanel::JSON::XS.\n    - Fixed a memory leak in Morbo. (heikojansen)\n    - Fixed Mojo::File::list_tree to no longer follow symbolic links to directories.\n\n- updated to 9.460.0 (9.46)\n    - Added random_bytes function to Mojo::Util. (leont)\n    - Improved randomness for CSRF token generation. (leont)\n    - Fixed tls_options handling in Mojo::IOLoop::TLS. (krauro)\n    - Fixed spec compliance issue with attribute selectors in Mojo::DOM::CSS.\n\n- updated to 9.450.0 (9.45)\n    - Fixed portability issue in WebSocket tests.\n    - Fixed various spec compliance issues in Mojo::DOM.\n    - Fixed permessage-deflate support in Mojo::Transaction::WebSocket to be more interoperable with non-spec compliant\n      implementations.\n    - Fixed punycode roundtrip bug in Mojo::Util.\n    - Fixed Windows compatibility issues of Mojo::File::list_tree.\n\n- updated to 9.420.0 (9.42)\n    - Un-deprecated the spurt method in Mojo::File, it is now an alternative to spew.\n    - Removed experimental status from top-level await support in Mojo::Promise.\n    - Removed experimental status from encrypted session cookie support.\n    - Removed experimental status from persistent cookie support.\n    - Removed experimental status from samesite cookie support.\n    - Removed experimental status from colourful log messages.\n    - Removed experimental status from freeze option in Mojo::IOLoop.\n    - Removed experimental status from check and raise functions in Mojo::Exception.\n    - Fixed Cpanel::JSON::XS compatibility issues. (ilmari)\n    - Fixed async/await memory leak in Mojo::Promise. (TFBW)\n","modified":"2026-07-31T14:01:33.665357923Z","published":"2026-07-27T08:04:32Z","withdrawn":"2026-07-31T14:01:33.665357681Z","related":["CVE-2026-15747"],"upstream":["CVE-2026-15747"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271431"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-15747"}],"affected":[{"package":{"name":"perl-Mojolicious","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/perl-Mojolicious&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.480.0-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"perl-Mojolicious":"9.480.0-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21451-1.json"}}],"schema_version":"1.7.5"}