CVE-2026-15747
Description
A flaw was found in Mojolicious. This vulnerability exposes a stable representation of the session Cross-Site Request Forgery (CSRF) token to a BREACH compression oracle. When a web server response containing the token is gzip-compressed and also echoes attacker-controlled input, an attacker can use the resulting compressed lengths to recover the CSRF token. This allows an attacker to bypass CSRF protection and potentially perform unauthorized actions.
Statement
Red Hat Product Security has determined that this vulnerability does not affect any currently supported Red Hat product. This assessment may evolve based on further analysis and discovery. For more information about this vulnerability and the products it affects, please see the linked references.
Understanding the Weakness (CWE)
Confidentiality,Access Control
Technical Impact: Read Application Data; Bypass Protection Mechanism
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.