Security update for perl-Mojolicious
This update for perl-Mojolicious fixes the following issues: Changes in perl-Mojolicious: - updated to 9.480.0 (9.48) - Fixed a security issue where CSRF tokens were vulnerable to BREACH attacks. Tokens are now masked with a fresh random value on every request, instead of being reused for the whole lifetime of a session. CVE-2026-15747 bsc#1271431 - updated to 9.470.0 (9.47) - Added support for the QUERY HTTP request method from RFC 10008. - Added query and query_p methods to Mojo::UserAgent. - Added query method to Mojolicious::Routes::Route. - Added query method to Mojolicious::Lite. - Added query_ok method to Test::Mojo. - Fixed a security issue where the pure-Perl implementation of Mojo::JSON could exhaust all available memory when decoding deeply nested data. Decoding is now limited to 512 levels of nesting, to match the default of Cpanel::JSON::XS. - Fixed a memory leak in Morbo. (heikojansen) - Fixed Mojo::File::list_tree to no longer follow symbolic links to directories. - updated to 9.460.0 (9.46) - Added random_bytes function to Mojo::Util. (leont) - Improved randomness for CSRF token generation. (leont) - Fixed tls_options handling in Mojo::IOLoop::TLS. (krauro) - Fixed spec compliance issue with attribute selectors in Mojo::DOM::CSS. - updated to 9.450.0 (9.45) - Fixed portability issue in WebSocket tests. - Fixed various spec compliance issues in Mojo::DOM. - Fixed permessage-deflate support in Mojo::Transaction::WebSocket to be more interoperable with non-spec compliant implementations. - Fixed punycode roundtrip bug in Mojo::Util. - Fixed Windows compatibility issues of Mojo::File::list_tree. - updated to 9.420.0 (9.42) - Un-deprecated the spurt method in Mojo::File, it is now an alternative to spew. - Removed experimental status from top-level await support in Mojo::Promise. - Removed experimental status from encrypted session cookie support. - Removed experimental status from persistent cookie support. - Removed experimental status from samesite cookie support. - Removed experimental status from colourful log messages. - Removed experimental status from freeze option in Mojo::IOLoop. - Removed experimental status from check and raise functions in Mojo::Exception. - Fixed Cpanel::JSON::XS compatibility issues. (ilmari) - Fixed async/await memory leak in Mojo::Promise. (TFBW)
Security update for perl-Mojolicious
Description
This update for perl-Mojolicious fixes the following issues: Changes in perl-Mojolicious: - updated to 9.480.0 (9.48) - Fixed a security issue where CSRF tokens were vulnerable to BREACH attacks. Tokens are now masked with a fresh random value on every request, instead of being reused for the whole lifetime of a session. CVE-2026-15747 bsc#1271431 - updated to 9.470.0 (9.47) - Added support for the QUERY HTTP request method from RFC 10008. - Added query and query_p methods to Mojo::UserAgent. - Added query method to Mojolicious::Routes::Route. - Added query method to Mojolicious::Lite. - Added query_ok method to Test::Mojo. - Fixed a security issue where the pure-Perl implementation of Mojo::JSON could exhaust all available memory when decoding deeply nested data. Decoding is now limited to 512 levels of nesting, to match the default of Cpanel::JSON::XS. - Fixed a memory leak in Morbo. (heikojansen) - Fixed Mojo::File::list_tree to no longer follow symbolic links to directories. - updated to 9.460.0 (9.46) - Added random_bytes function to Mojo::Util. (leont) - Improved randomness for CSRF token generation. (leont) - Fixed tls_options handling in Mojo::IOLoop::TLS. (krauro) - Fixed spec compliance issue with attribute selectors in Mojo::DOM::CSS. - updated to 9.450.0 (9.45) - Fixed portability issue in WebSocket tests. - Fixed various spec compliance issues in Mojo::DOM. - Fixed permessage-deflate support in Mojo::Transaction::WebSocket to be more interoperable with non-spec compliant implementations. - Fixed punycode roundtrip bug in Mojo::Util. - Fixed Windows compatibility issues of Mojo::File::list_tree. - updated to 9.420.0 (9.42) - Un-deprecated the spurt method in Mojo::File, it is now an alternative to spew. - Removed experimental status from top-level await support in Mojo::Promise. - Removed experimental status from encrypted session cookie support. - Removed experimental status from persistent cookie support. - Removed experimental status from samesite cookie support. - Removed experimental status from colourful log messages. - Removed experimental status from freeze option in Mojo::IOLoop. - Removed experimental status from check and raise functions in Mojo::Exception. - Fixed Cpanel::JSON::XS compatibility issues. (ilmari) - Fixed async/await memory leak in Mojo::Promise. (TFBW)
Affected software
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- SUSE Product Security Team
- Advisory Id
- openSUSE-SU-2026:21496-1
- Cve Count
- 1
- State
- PUBLISHED
Threat ID: 6aab496555bf5e2cf5990cf4
Added to database: 09/17/2026, 01:59:01 UTC
Last updated: 09/17/2026, 02:02:23 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.