#1141638 HTTP::Tiny: CVE-2026-7017

Package:
src:libhttp-tiny-perl
Source:
src:libhttp-tiny-perl
Submitter:
Salvatore Bonaccorso
Date:
2026-09-02 21:19:07 UTC
Severity:
normal
Tags:
#1141638#5
Date:
2026-07-07 19:16:51 UTC
From:
To:
Hi,

The following vulnerability was published for libhttp-tiny-perl.

CVE-2026-7017[0]:
| HTTP::Tiny versions before 0.095 for Perl forward credential headers
| to cross-origin redirect targets.  When the server returns a 3xx
| redirect, `_maybe_redirect` follows the `Location:` header and
| `_prepare_headers_and_cb` re-merges the caller's `headers` argument
| into the new request, without checking whether the redirect target
| shares an origin with the original URL. Caller-supplied
| `Authorization`, `Cookie` and `Proxy-Authorization` headers are
| therefore re-sent to whatever host the redirect names, across
| scheme, host or port boundaries, and including `https` to `http`
| downgrades that expose them in plaintext on the wire.  The
| HTTP::Tiny POD note that "Authorization headers will not be included
| in a redirected request" applied only to the URL-userinfo Basic-auth
| path, not to headers passed explicitly by the caller.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-7017
https://www.cve.org/CVERecord?id=CVE-2026-7017
[1] https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/pull/36
[2] https://lists.security.metacpan.org/cve-announce/msg/41618211/

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1141638#18
Date:
2026-07-08 17:04:27 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
libhttp-tiny-perl, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1141638@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
gregor herrmann <gregoa@debian.org> (supplier of updated libhttp-tiny-perl package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Wed, 08 Jul 2026 18:42:44 +0200
Source: libhttp-tiny-perl
Architecture: source
Version: 0.096-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Perl Group <pkg-perl-maintainers@lists.alioth.debian.org>
Changed-By: gregor herrmann <gregoa@debian.org>
Closes: 1141638
Changes:
 libhttp-tiny-perl (0.096-1) unstable; urgency=medium
 .
   * Import upstream version 0.096.
     Includes fix for CVE-2026-7017 since 0.095.
     Closes: #1141638
   * Drop debian/patches/CVE-2026-7010-*.patch.
     These patches were taken from upstream Git and are included in
     the 0.093 release.
   * Update years of upstream copyright.
Checksums-Sha1:
 6a384e4b0acddbd4ddbad5e971c85827beaa2c10 2525 libhttp-tiny-perl_0.096-1.dsc
 2095f2557627f1db6cbbb3f371526e8152fd7e73 81773 libhttp-tiny-perl_0.096.orig.tar.gz
 f93e571537951934735ec58a9d43b10d74e9fb2f 5152 libhttp-tiny-perl_0.096-1.debian.tar.xz
Checksums-Sha256:
 29038608e753cc2d8fc92abe0efe31e5ca3323fe29645358cdacead772197ef2 2525 libhttp-tiny-perl_0.096-1.dsc
 1df1a8caecbf97a2cbe002a655e0fe21d4cd5bbee9e40656a3a602423f98eaef 81773 libhttp-tiny-perl_0.096.orig.tar.gz
 52389182e1f2e9b08644f6bd92ccb662b782239c7fca588008473a30c6e6b172 5152 libhttp-tiny-perl_0.096-1.debian.tar.xz
Files:
 c24b50de8216b81bc718386d59c0abd8 2525 perl optional libhttp-tiny-perl_0.096-1.dsc
 7a2c39293ccd0e0b3fd8d065f5b6ba3c 81773 perl optional libhttp-tiny-perl_0.096.orig.tar.gz
 ef9bbfedf51b7f8cb1c0f3921b20402d 5152 perl optional libhttp-tiny-perl_0.096-1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEE0eExbpOnYKgQTYX6uzpoAYZJqgYFAmpOf49fFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEQx
RTEzMTZFOTNBNzYwQTgxMDREODVGQUJCM0E2ODAxODY0OUFBMDYACgkQuzpoAYZJ
qga6Dw/+LnGZP4IDuFoJtEGazaMhBAfqPBuTJiAvK2mYg+X+Yg9ojnblDTGffs7n
BV+jk8qljupUcgQLC+cnSGbFGPKa8d6EYWZfZjQDhOhTWWj0eTc/XdCHzxZf5lOC
oPZ/QsGD9wSxojeOJ6A+xfV6WB4+X5j1Dj4q6lK+EItW1JOgNKcLnA9L7mquOT43
zgo5xG3YainWlcl8kfu19Cii6bIuwJ2zMk5nnkEYHYP4EXmiSwquJLRSIc4fU+Oq
JWp8cxsYOwFrPvePmqSCfmqvLZGC3nrrrDxGtXKJW98dlGH238ogE2ASROC09AMS
uSb7odfO1VnS8WQj8No1kzmQ7ShW8mj5uJ22jfLJmITflyri1/Dw8Ouwr1BQ9w6I
ectvq6c3i2OmJvTgapjomUHwuO/8fH+AJdu0V/OAkI4xOMy/Fl+TYDFpdiQH8nKn
YQxbLoyr8ALlmXao7eFD1rJl/ff7LLtKosJnqTNHw0uSkTr/jnVOftGR9cnLXqQE
ljZtaEV7EYuZ7DHAEQ+YL6eF7qFWwFvrhPJDMiYjvXv/T6babzb6aAcYSs+Nixd2
J8dDvr6gM/zfDw+qkL+YoQxHSbwSzmXIlBuxNyuayiKQ+n2mEQ0EglSlw5SqWqvI
E0NBJEq62sBLWocTxqbW7qH1Co9auy3MApchrKWJOINqMKckh2s=
=CjnY
-----END PGP SIGNATURE-----

#1141638#23
Date:
2026-09-02 21:17:07 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
libhttp-tiny-perl, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1141638@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
gregor herrmann <gregoa@debian.org> (supplier of updated libhttp-tiny-perl package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Mon, 31 Aug 2026 16:34:43 +0200
Source: libhttp-tiny-perl
Architecture: source
Version: 0.090-1+deb13u1
Distribution: trixie
Urgency: medium
Maintainer: Debian Perl Group <pkg-perl-maintainers@lists.alioth.debian.org>
Changed-By: gregor herrmann <gregoa@debian.org>
Closes: 1141638 1146064
Changes:
 libhttp-tiny-perl (0.090-1+deb13u1) trixie; urgency=medium
 .
   * [Security] CVE-2026-7010: CRLF-validation in HTTP::Tiny.
     (Closes: #1146064)
   * [Security] CVE-2026-7017: HTTP::Tiny credential forwarding on
     redirects.
     (Closes: #1141638)
Checksums-Sha1:
 217a0bea18fb416d7a1facdaaf8100cd2ee078c5 2565 libhttp-tiny-perl_0.090-1+deb13u1.dsc
 0e0b01116ea65e26d06efc871f1e91ebda516238 9416 libhttp-tiny-perl_0.090-1+deb13u1.debian.tar.xz
Checksums-Sha256:
 16adcdd62cac5168ce7278301eb9e087b876cd696c2c866929f055b67e664aef 2565 libhttp-tiny-perl_0.090-1+deb13u1.dsc
 b72f6bd5ec049293bdbdc2d867d4d353c6aa3ba38b305c1902a73a718ebc249e 9416 libhttp-tiny-perl_0.090-1+deb13u1.debian.tar.xz
Files:
 52b049b62120992d185841b22912a3d3 2565 perl optional libhttp-tiny-perl_0.090-1+deb13u1.dsc
 2efe7104a38d1b2a400556b750bc65c0 9416 perl optional libhttp-tiny-perl_0.090-1+deb13u1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----

iQKSBAEBCgB9FiEE0eExbpOnYKgQTYX6uzpoAYZJqgYFAmqXSNhfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEQx
RTEzMTZFOTNBNzYwQTgxMDREODVGQUJCM0E2ODAxODY0OUFBMDYACgkQuzpoAYZJ
qgZlKQ/3U4MCU/hU9pMWSKmQfFELXKI9bapQ+91qJrEoRwcHFp9ZZIyL4fuVVCs2
WAuC4OeWUnXrrTZjgXKouG376WYjT2yM9WO1874JgLe/NtjLJohKiy6ZoiAx1fXC
fRqnIt5AqYBCt7jnklVLvTvDXkc19cd8rGHKvWdsBArJTTfxhk0jWB1bPkyhcm9w
rDG1XG+7pNZXL2Th0nBdpTdBWp0Qak4sZ08PzUD9VA3ALjSsE2YVwAuWPYIJqBLt
4pBax58KuS36h23HPxAIYQdRO10lh4jxSKaYWu8dIn4pT+p0AMFHeILmMh3VmEuQ
teP2Rl1fr7D8UIaVvxhUFCo4LUwbByoQBNhsv2pHhMfrCxfo4avsfI4DxZ5g8Y2c
0vZ8CeQRWyTSO/ZcFOvVGvmWX9ydksDMTxdpjzx1DLzJtVc+C8KIn//0mAKLYAqZ
GFwQd9XjkbxHxM+mIAOce1/Yl6IFzyzTUizh0d2TTicGToYoejxEstennpr5lPBT
aApQEnPv6HHlHJ5TW784PaSabvZdRhhaQU2hdKI9pMYwsoNRm8j4KQJIdBgvxics
NtIr16N/fyuajdx4i3632tjjwWXh7SdU8aLgVSLEGo95MVUY+sAAC7dyD/0QOTHu
C3+5BJMC83dyQy3X72Hz0Cqnl47nahAy5P925kQUyhvRNS7xjg==
=O9J3
-----END PGP SIGNATURE-----