openSUSE 16 Security Update : perl-Mojolicious (openSUSE-SU-2026:21451-1)

critical Nessus Plugin ID 330585

Synopsis

The remote openSUSE host is missing a security update.

Description

The remote openSUSE 16 host has a package installed that is affected by a vulnerability as referenced in the openSUSE- SU-2026:21451-1 advisory.

Changes in perl-Mojolicious:

- updated to 9.480.0 (9.48)
- Fixed a security issue where CSRF tokens were vulnerable to BREACH attacks. Tokens are now masked with a fresh random value on every request, instead of being reused for the whole lifetime of a session.
CVE-2026-15747 bsc#1271431

- updated to 9.470.0 (9.47)
- Added support for the QUERY HTTP request method from RFC 10008.
- Added query and query_p methods to Mojo::UserAgent.
- Added query method to Mojolicious::Routes::Route.
- Added query method to Mojolicious::Lite.
- Added query_ok method to Test::Mojo.
- Fixed a security issue where the pure-Perl implementation of Mojo::JSON could exhaust all available memory when decoding deeply nested data. Decoding is now limited to 512 levels of nesting, to match the default of Cpanel::JSON::XS.
- Fixed a memory leak in Morbo. (heikojansen)
- Fixed Mojo::File::list_tree to no longer follow symbolic links to directories.

- updated to 9.460.0 (9.46)
- Added random_bytes function to Mojo::Util. (leont)
- Improved randomness for CSRF token generation. (leont)
- Fixed tls_options handling in Mojo::IOLoop::TLS. (krauro)
- Fixed spec compliance issue with attribute selectors in Mojo::DOM::CSS.

- updated to 9.450.0 (9.45)
- Fixed portability issue in WebSocket tests.
- Fixed various spec compliance issues in Mojo::DOM.
- Fixed permessage-deflate support in Mojo::Transaction::WebSocket to be more interoperable with non- spec compliant implementations.
- Fixed punycode roundtrip bug in Mojo::Util.
- Fixed Windows compatibility issues of Mojo::File::list_tree.

- updated to 9.420.0 (9.42)
- Un-deprecated the spurt method in Mojo::File, it is now an alternative to spew.
- Removed experimental status from top-level await support in Mojo::Promise.
- Removed experimental status from encrypted session cookie support.
- Removed experimental status from persistent cookie support.
- Removed experimental status from samesite cookie support.
- Removed experimental status from colourful log messages.
- Removed experimental status from freeze option in Mojo::IOLoop.
- Removed experimental status from check and raise functions in Mojo::Exception.
- Fixed Cpanel::JSON::XS compatibility issues. (ilmari)
- Fixed async/await memory leak in Mojo::Promise. (TFBW)

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Update the affected perl-Mojolicious package.

See Also

https://bugzilla.suse.com/1271431

https://www.suse.com/security/cve/CVE-2026-15747

Plugin Details

Severity: Critical

ID: 330585

File Name: openSUSE-2026-21451-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 7/29/2026

Updated: 7/29/2026

Supported Sensors: Continuous Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.62

CVSS v2

Risk Factor: High

Base Score: 9.4

Temporal Score: 7

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:N

CVSS Score Source: CVE-2026-15747

CVSS v3

Risk Factor: Critical

Base Score: 9.1

Temporal Score: 7.9

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:novell:opensuse:16.0, p-cpe:/a:novell:opensuse:perl-mojolicious

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 7/27/2026

Vulnerability Publication Date: 7/14/2026

Reference Information

CVE: CVE-2026-15747