Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6cg9-7rr8-cvj2

Опубликовано: 14 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH compression oracle.

_csrf_token generates and caches one token per session and returns the same value on every call, and _csrf_field places that value in a hidden csrf_token input. When a response carrying the token also echoes attacker-controlled input and is gzip-compressed, the chosen values and the resulting compressed lengths form a BREACH oracle.

An attacker able to query it can recover the token and pass csrf_protect validation.

Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH compression oracle.

_csrf_token generates and caches one token per session and returns the same value on every call, and _csrf_field places that value in a hidden csrf_token input. When a response carrying the token also echoes attacker-controlled input and is gzip-compressed, the chosen values and the resulting compressed lengths form a BREACH oracle.

An attacker able to query it can recover the token and pass csrf_protect validation.

EPSS

Процентиль: 17%
0.00255
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-204

Связанные уязвимости

CVSS3: 9.1
ubuntu
около 1 месяца назад

Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH compression oracle. _csrf_token generates and caches one token per session and returns the same value on every call, and _csrf_field places that value in a hidden `csrf_token` input. When a response carrying the token also echoes attacker-controlled input and is gzip-compressed, the chosen values and the resulting compressed lengths form a BREACH oracle. An attacker able to query it can recover the token and pass csrf_protect validation.

CVSS3: 9.1
nvd
около 1 месяца назад

Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH compression oracle. _csrf_token generates and caches one token per session and returns the same value on every call, and _csrf_field places that value in a hidden `csrf_token` input. When a response carrying the token also echoes attacker-controlled input and is gzip-compressed, the chosen values and the resulting compressed lengths form a BREACH oracle. An attacker able to query it can recover the token and pass csrf_protect validation.

CVSS3: 9.1
debian
около 1 месяца назад

Mojolicious versions from 4.59 before 9.48 for Perl expose a stable re ...

suse-cvrf
25 дней назад

Security update for perl-Mojolicious

suse-cvrf
27 дней назад

Security update for perl-Mojolicious

EPSS

Процентиль: 17%
0.00255
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-204