|
|
Message-Id: <7B389E09-9A47-49DF-95AC-772AC2F98968@stig.io>
Date: Tue, 12 May 2026 16:07:16 +0200
From: Stig Palmquist <stig@...g.io>
To: cve-announce@...urity.metacpan.org,
oss-security@...ts.openwall.com
Subject: CVE-2026-8368: LWP::UserAgent versions before 6.83 for Perl leak
Authorization and Proxy-Authorization headers on cross-origin redirects
========================================================================
CVE-2026-8368 CPAN Security Group
========================================================================
CVE ID: CVE-2026-8368
Distribution: libwww-perl
Versions: before 6.83
MetaCPAN: https://metacpan.org/dist/libwww-perl
VCS Repo: https://github.com/libwww-perl/libwww-perl
LWP::UserAgent versions before 6.83 for Perl leak Authorization and
Proxy-Authorization headers on cross-origin redirects
Description
-----------
LWP::UserAgent versions before 6.83 for Perl leak Authorization and
Proxy-Authorization headers on cross-origin redirects.
On a 3xx response, the redirect handler strips only Host and Cookie
before issuing the follow-up request. Caller-supplied Authorization and
Proxy-Authorization headers are sent unchanged to the redirect target,
including across scheme, host, or port changes.
A redirect to an attacker controlled host therefore discloses the
caller's credentials to that host.
Problem types
-------------
- CWE-522 Insufficiently Protected Credentials
Solutions
---------
Upgrade to libwww-perl 6.83 or later.
References
----------
https://github.com/libwww-perl/libwww-perl/commit/9c4aeb6f2dd32f2b7eaf2d7827cade31ea6cb2c6.patch
https://metacpan.org/release/OALDERS/libwww-perl-6.83/changes
https://github.com/libwww-perl/libwww-perl/pull/512
https://github.com/libwww-perl/libwww-perl/pull/284
Timeline
--------
- 2026-05-11: Issue reported.
- 2026-05-12: libwww-perl 6.83 released with fix.
Credits
-------
Kai Aizen, reporter
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.