Executive brief
Mojo::JWT is a Perl library used to handle JSON Web Tokens, which are commonly used for user authentication and secure data exchange. A flaw in how the library verifies security signatures allows an attacker to potentially guess valid signatures by measuring tiny differences in the time it takes for the server to respond. If successful, an attacker could forge their own tokens to bypass authentication or impersonate other users.
Technical details
The decode() method in Mojo::JWT uses Perl's 'eq' operator to compare a supplied HMAC signature against the recomputed signature. Because 'eq' is not a constant-time comparison operator, it returns as soon as it finds a differing byte, creating an observable timing discrepancy (CWE-208). An attacker can exploit this by sending many crafted tokens and measuring response times to iteratively determine the correct signature bytes. This allows for the forgery of valid JWTs without knowing the secret key. The issue is fixed in version 1.02.
Affected products
- JBERGER Mojo::JWT < 1.02
Timeline
- 2026-07-17: disclosed
- 2026-07-17: advisory