Back

MEDIUM

Mojo::JWT versions before 1.02 for Perl verify HMAC signatures with a non-constant-time string comparison

Published Jul 17, 2026

Description

Mojo::JWT versions before 1.02 for Perl verify HMAC signatures with a non-constant-time string comparison.

The decode() method compares the supplied signature to the recomputed HMAC with Perl's eq operator, which stops at the first differing byte, so the comparison time varies with the number of matching leading bytes.

A caller that decodes attacker supplied tokens leaks the expected signature through this timing variation, which can be aggregated over many requests to recover the signature and forge a token.

Affected products

Remediation

Vendor solution

Upgrade to Mojo-JWT 1.02, which compares signatures with the constant-time Mojo::Util::secure_compare.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner CPANSec
Published Jul 17, 2026
Updated Jul 20, 2026
Reserved May 25, 2026
CISA Vulnrichment
Updated Jul 20, 2026
NVD
Status Deferred
Modified Jul 20, 2026
Red Hat
Severity n/a
Public date n/a