| Release | Version | 
|---|---|
| bullseye | 8.71+dfsg-1 | 
| bookworm | 9.31+dfsg-1 | 
| trixie | 9.39+dfsg-1 | 
| forky | 9.39+dfsg-1 | 
| sid | 9.39+dfsg-1 | 
| Bug | bullseye | bookworm | trixie | forky | sid | Description | 
|---|---|---|---|---|---|---|
| CVE-2024-58135 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | vulnerable (no DSA) | vulnerable | vulnerable | Mojolicious versions from 7.28 for Perl will generate weak HMAC sessio ... | 
| CVE-2024-58134 | vulnerable (no DSA, ignored) | vulnerable (no DSA) | vulnerable (no DSA) | vulnerable | vulnerable | Mojolicious versions from 0.999922 for Perl uses a hard coded string, ... | 
| CVE-2021-47208 | vulnerable (no DSA, ignored) | fixed | fixed | fixed | fixed | The Mojolicious module before 9.11 for Perl has a bug in format detect ... | 
| Bug | Description | 
|---|---|
| CVE-2020-36829 | The Mojolicious module before 8.65 for Perl is vulnerable to secure_co ... | 
| CVE-2018-25100 | The Mojolicious module before 7.66 for Perl may leak cookies in certai ... | 
| CVE-2011-1841 | Cross-site scripting (XSS) vulnerability in the link_to helper in Mojo ... | 
| CVE-2011-1589 | Directory traversal vulnerability in Path.pm in Mojolicious before 1.1 ... | 
| CVE-2010-4803 | Mojolicious before 0.999927 does not properly implement HMAC-MD5 check ... | 
| CVE-2010-4802 | Commands.pm in Mojolicious before 0.999928 does not properly perform C ... | 
| CVE-2009-5074 | Unspecified vulnerability in the MojoX::Dispatcher::Static implementat ... | 
| DSA / DLA | Description | 
|---|---|
| DLA-3846-1 | libmojolicious-perl - security update | 
| DSA-2239-1 | libmojolicious-perl - several | 
| DSA-2221-1 | libmojolicious-perl - directory traversal |