- Package:
- libhttp-tiny-perl
- Source:
- libhttp-tiny-perl
- Submitter:
- Niko Tyni
- Date:
- 2026-09-02 21:19:11 UTC
- Severity:
- normal
- Tags:
Package: perl Version: 5.40.1-6 Severity: important Tags: security upstream X-Debbugs-Cc: carnil@debian.org, libhttp-tiny-perl@packages.debian.org Forwarded: https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/d73c7651e82ace02693842df55928b6c3ae7c38d Control: found -1 5.32.1-4 Control: found -1 5.36.0-1 Control: found -1 5.42.2-1 The following vulnerability was published[0] for HTTP-Tiny: CVE ID: CVE-2026-7010 Distribution: HTTP-Tiny Versions: before 0.093 MetaCPAN: https://metacpan.org/dist/HTTP-Tiny VCS Repo: https://github.com/Perl-Toolchain-Gang/HTTP-Tiny HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values. The unvalidated inputs are the method and URI in the request line, the URL host that becomes the `Host:` header, and HTTP/1.1 control data field values. An attacker who controls one of these inputs, for example a user supplied URL passed to a webhook or URL fetch endpoint, can inject additional headers and smuggle requests to the upstream server. This CPAN module is shipped in both libhttp-tiny-perl and perl. The libhttp-tiny-perl package was already fixed for sid + forky in version 0.092-2. The issue is marked as no-dsa in the security tracker [1]. Copying the libhttp-tiny-perl maintainers, and Salvatore for his security hat. I suppose we can manage without a separate libhttp-tiny-perl bug at this point, but feel free to clone one if it helps. [0] https://lists.security.metacpan.org/cve-announce/msg/39952806/ [1] https://security-tracker.debian.org/tracker/CVE-2026-7010
We believe that the bug you reported is fixed in the latest version of
perl, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1138858@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Niko Tyni <ntyni@debian.org> (supplier of updated perl package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sat, 06 Jun 2026 17:22:29 +0300
Source: perl
Architecture: source
Version: 5.40.1-8
Distribution: unstable
Urgency: medium
Maintainer: Niko Tyni <ntyni@debian.org>
Changed-By: Niko Tyni <ntyni@debian.org>
Closes: 1137345 1138854 1138855 1138856 1138858 1138863 1138905 1138906
Changes:
perl (5.40.1-8) unstable; urgency=medium
.
* [SECURITY] backport various fixes from upstream:
+ CVE-2025-15649: header parsing in IO::Uncompress::Unzip.
(Closes: #1138863)
+ CVE-2026-7010: CRLF-validation in HTTP::Tiny.
(Closes: #1138858)
+ CVE-2026-8376: Buffer overflow in Perl_study_chunk.
(Closes: #1137345)
+ CVE-2026-48959: CPU exhaustion in IO::Uncompress::Unzip.
(Closes: #1138856)
+ CVE-2026-48961: crash in zipdetails.
(Closes: #1138855)
+ CVE-2026-48962: code execution in IO-Compress via output globs.
(Closes: #1138854)
+ buffer overflows in pack().
(Closes: #1138905)
+ buffer overflow in Storable.
(Closes: #1138906)
Checksums-Sha1:
feff9b43463d196f6744b2f51ab3094537900678 2372 perl_5.40.1-8.dsc
a275dffed86a0d9a43dc87b7ffec3a03b8aab38d 179088 perl_5.40.1-8.debian.tar.xz
efc987732ec29a37204e0cc26d43d761be2671d3 5338 perl_5.40.1-8_source.buildinfo
Checksums-Sha256:
0df3684ddbed6c62651b8f682df33d2af54d47ee238958f30fa26ac066ee88d5 2372 perl_5.40.1-8.dsc
621e16fec9e822ec835071aa3665ebd329142bcd270b86a6f9bb04cb94a1de08 179088 perl_5.40.1-8.debian.tar.xz
bbf2de68263b588b9b82209e60f9ed9704f7021ffa9b08fab2da43f9c9485b93 5338 perl_5.40.1-8_source.buildinfo
Files:
d9d1456beca9bb3f5535b82405708bfe 2372 perl standard perl_5.40.1-8.dsc
46569b65055e962347a20985b9ec245a 179088 perl standard perl_5.40.1-8.debian.tar.xz
ffcf467b4231949b678af8c4ae3651e3 5338 perl standard perl_5.40.1-8_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iKcEARMJAC8WIQTuZv2Xfg2x/uVxefeK/rNkDrE5sgUCaiRB+hEcbnR5bmlAZGVi
aWFuLm9yZwAKCRCK/rNkDrE5st5SAX9cPTfxh8ivQ7d4IBnal//ySr/1+zI8TyyB
J09rCB4SqkDM74u0tZtsSeIXuILCJ5UBgKav4TN0s0BVQ/Kv78fVzoAvLfYtm7dn
nojCgyWR8Nw+dYy5Gg04H/JmVY8GWBMzpA==
=Vizr
-----END PGP SIGNATURE-----
We believe that the bug you reported is fixed in the latest version of
perl, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1138858@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Niko Tyni <ntyni@debian.org> (supplier of updated perl package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sat, 06 Jun 2026 18:02:30 +0300
Source: perl
Architecture: source
Version: 5.42.2-2
Distribution: experimental
Urgency: medium
Maintainer: Niko Tyni <ntyni@debian.org>
Changed-By: Niko Tyni <ntyni@debian.org>
Closes: 1137345 1138854 1138855 1138856 1138858 1138863 1138905 1138906
Changes:
perl (5.42.2-2) experimental; urgency=medium
.
* [SECURITY] backport various fixes from upstream:
+ CVE-2025-15649: header parsing in IO::Uncompress::Unzip.
(Closes: #1138863)
+ CVE-2026-7010: CRLF-validation in HTTP::Tiny.
(Closes: #1138858)
+ CVE-2026-8376: Buffer overflow in Perl_study_chunk.
(Closes: #1137345)
+ CVE-2026-48959: CPU exhaustion in IO::Uncompress::Unzip.
(Closes: #1138856)
+ CVE-2026-48961: crash in zipdetails.
(Closes: #1138855)
+ CVE-2026-48962: code execution in IO-Compress via output globs.
(Closes: #1138854)
+ buffer overflows in pack().
(Closes: #1138905)
+ buffer overflow in Storable.
(Closes: #1138906)
Checksums-Sha1:
fac7a2aa4e40bb502f1d0ce479f05bb76f4e7fe1 2372 perl_5.42.2-2.dsc
9060d73f124395f973a8cfe3d6e412fbb93217ce 175608 perl_5.42.2-2.debian.tar.xz
9cea33e3faf2aceb567e9db40aa4fff67e9264ad 5338 perl_5.42.2-2_source.buildinfo
Checksums-Sha256:
e33c40124c7932ccebc7343c768e74347545dabf04b48a7b94a3b8d1a829a15c 2372 perl_5.42.2-2.dsc
03dc1d547aa8271832042b2a66b8c71a72035c28ca736166fd27dc6d2aaa8afb 175608 perl_5.42.2-2.debian.tar.xz
1b9c3872189b57ee52820e2d497dd8e99fdfb243e03a872f0013322a801380b2 5338 perl_5.42.2-2_source.buildinfo
Files:
13b7988bfedecc286305774e1817e7d0 2372 perl standard perl_5.42.2-2.dsc
0a7ad2361cdc8b893dbcad3628bcd09f 175608 perl standard perl_5.42.2-2.debian.tar.xz
8ed1e5c781a84858dfb01c5d963d86a3 5338 perl standard perl_5.42.2-2_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iKcEARMJAC8WIQTuZv2Xfg2x/uVxefeK/rNkDrE5sgUCaiRCvBEcbnR5bmlAZGVi
aWFuLm9yZwAKCRCK/rNkDrE5soOOAXoDqPuy2hIDNgbVMnotKgfi7tU1TjmeDkEC
OfUCv1UOU/zgnn4mqFkVY0EtjSc74iUBf3LHLX7Tab7loNX6UtKcvkCmoY1uXvWf
a7YWnv6aOXsw9oPetRDgHQcOE9AHI6Mz8w==
=YN5x
-----END PGP SIGNATURE-----
We believe that the bug you reported is fixed in the latest version of
libhttp-tiny-perl, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1146064@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
gregor herrmann <gregoa@debian.org> (supplier of updated libhttp-tiny-perl package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Mon, 31 Aug 2026 16:34:43 +0200
Source: libhttp-tiny-perl
Architecture: source
Version: 0.090-1+deb13u1
Distribution: trixie
Urgency: medium
Maintainer: Debian Perl Group <pkg-perl-maintainers@lists.alioth.debian.org>
Changed-By: gregor herrmann <gregoa@debian.org>
Closes: 1141638 1146064
Changes:
libhttp-tiny-perl (0.090-1+deb13u1) trixie; urgency=medium
.
* [Security] CVE-2026-7010: CRLF-validation in HTTP::Tiny.
(Closes: #1146064)
* [Security] CVE-2026-7017: HTTP::Tiny credential forwarding on
redirects.
(Closes: #1141638)
Checksums-Sha1:
217a0bea18fb416d7a1facdaaf8100cd2ee078c5 2565 libhttp-tiny-perl_0.090-1+deb13u1.dsc
0e0b01116ea65e26d06efc871f1e91ebda516238 9416 libhttp-tiny-perl_0.090-1+deb13u1.debian.tar.xz
Checksums-Sha256:
16adcdd62cac5168ce7278301eb9e087b876cd696c2c866929f055b67e664aef 2565 libhttp-tiny-perl_0.090-1+deb13u1.dsc
b72f6bd5ec049293bdbdc2d867d4d353c6aa3ba38b305c1902a73a718ebc249e 9416 libhttp-tiny-perl_0.090-1+deb13u1.debian.tar.xz
Files:
52b049b62120992d185841b22912a3d3 2565 perl optional libhttp-tiny-perl_0.090-1+deb13u1.dsc
2efe7104a38d1b2a400556b750bc65c0 9416 perl optional libhttp-tiny-perl_0.090-1+deb13u1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----
iQKSBAEBCgB9FiEE0eExbpOnYKgQTYX6uzpoAYZJqgYFAmqXSNhfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEQx
RTEzMTZFOTNBNzYwQTgxMDREODVGQUJCM0E2ODAxODY0OUFBMDYACgkQuzpoAYZJ
qgZlKQ/3U4MCU/hU9pMWSKmQfFELXKI9bapQ+91qJrEoRwcHFp9ZZIyL4fuVVCs2
WAuC4OeWUnXrrTZjgXKouG376WYjT2yM9WO1874JgLe/NtjLJohKiy6ZoiAx1fXC
fRqnIt5AqYBCt7jnklVLvTvDXkc19cd8rGHKvWdsBArJTTfxhk0jWB1bPkyhcm9w
rDG1XG+7pNZXL2Th0nBdpTdBWp0Qak4sZ08PzUD9VA3ALjSsE2YVwAuWPYIJqBLt
4pBax58KuS36h23HPxAIYQdRO10lh4jxSKaYWu8dIn4pT+p0AMFHeILmMh3VmEuQ
teP2Rl1fr7D8UIaVvxhUFCo4LUwbByoQBNhsv2pHhMfrCxfo4avsfI4DxZ5g8Y2c
0vZ8CeQRWyTSO/ZcFOvVGvmWX9ydksDMTxdpjzx1DLzJtVc+C8KIn//0mAKLYAqZ
GFwQd9XjkbxHxM+mIAOce1/Yl6IFzyzTUizh0d2TTicGToYoejxEstennpr5lPBT
aApQEnPv6HHlHJ5TW784PaSabvZdRhhaQU2hdKI9pMYwsoNRm8j4KQJIdBgvxics
NtIr16N/fyuajdx4i3632tjjwWXh7SdU8aLgVSLEGo95MVUY+sAAC7dyD/0QOTHu
C3+5BJMC83dyQy3X72Hz0Cqnl47nahAy5P925kQUyhvRNS7xjg==
=O9J3
-----END PGP SIGNATURE-----