Executive brief
Mojolicious, a popular web framework for the Perl programming language, was found to use static CSRF tokens that are vulnerable to a side-channel attack known as BREACH. When a web page uses gzip compression and includes both a static security token and attacker-controlled text, an attacker can monitor the size of the encrypted traffic to guess the security token. If successful, the attacker can bypass Cross-Site Request Forgery (CSRF) protections, potentially allowing them to perform unauthorized actions on behalf of a logged-in user.
Technical details
Mojolicious versions 4.59 before 9.48 are vulnerable to a BREACH (Browser Reconnaissance and Exfiltration via Adaptive Compression of Hypertext) attack. The framework's `_csrf_token` helper generates and caches a single token per session, which is then embedded in responses via `_csrf_field`. When these responses are gzip-compressed and contain attacker-controlled reflected input, the compression ratio creates a side-channel oracle. By observing the length of compressed responses for various guesses, a remote attacker can recover the CSRF token and bypass `csrf_protect` validation. The issue is resolved in version 9.48 by masking the token with a fresh random value on every request.
Affected products
- SRI Mojolicious 4.59 to 9.47
Timeline
- 2026-07-14: advisory: CVE-2026-15747 published
- 2026-07-14: patched: Fixed in Mojolicious version 9.48