CVE-2026-7017

ADVISORY - debian

Summary

HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets. When the server returns a 3xx redirect, _maybe_redirect follows the Location: header and _prepare_headers_and_cb re-merges the caller's headers argument into the new request, without checking whether the redirect target shares an origin with the original URL. Caller-supplied Authorization, Cookie and Proxy-Authorization headers are therefore re-sent to whatever host the redirect names, across scheme, host or port boundaries, and including https to http downgrades that expose them in plaintext on the wire. The HTTP::Tiny POD note that "Authorization headers will not be included in a redirected request" applied only to the URL-userinfo Basic-auth path, not to headers passed explicitly by the caller.


EPSS Score: 0.00247 (0.161)

Common Weakness Enumeration (CWE)


Debian

CREATED

UPDATED

ADVISORY IDCVE-2026-7017
EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM ADVISORY
PackageTypeOS NameOS VersionAffected RangesFix Versions
debian/perldebdebian12>0Not yet available
debian/libhttp-tiny-perldebdebianunstable<0.096-10.096-1
debian/libhttp-tiny-perldebdebian13<0.090-1+deb13u10.090-1+deb13u1
debian/libhttp-tiny-perldebdebian14<0.096-10.096-1
debian/libhttp-tiny-perldebdebian12>0Not yet available
debian/perldebdebian13<5.40.1-6+deb13u15.40.1-6+deb13u1
debian/perldebdebian14<5.42.3-15.42.3-1
debian/perldebdebianunstable<5.42.3-15.42.3-1

Severity and metrics

No CVSS data available from this advisory.

Ubuntu

CREATED

UPDATED

ADVISORY IDCVE-2026-7017
EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Amedium