I've uploaded libhttp-tiny-perl/0.090-1+deb13u1 to trixie, in the
hope that in can be included in the upcoming point release.
This upload has been prepared in cooperation with ntyni and carnil
and is part of the Perl no-DSA security fixes, as decribed in
#1146369.
This upload fixes #1146064 aka CVE-2026-7010 and #1141638 aka
CVE-2026-7017.
All patches are identical (modulo paths and bug numbers) to the ones
in src:perl (I copied them from there :)) and are taken from upstream
commits which are already released in newer versions of
libhttp-tiny-perl.
Changelog entry:
#v+
libhttp-tiny-perl (0.090-1+deb13u1) trixie; urgency=medium
* [Security] CVE-2026-7010: CRLF-validation in HTTP::Tiny.
(Closes: #1146064)
* [Security] CVE-2026-7017: HTTP::Tiny credential forwarding on
redirects.
(Closes: #1141638)
-----BEGIN PGP SIGNATURE-----
iQKTBAEBCgB9FiEE0eExbpOnYKgQTYX6uzpoAYZJqgYFAmqXTfpfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEQx
RTEzMTZFOTNBNzYwQTgxMDREODVGQUJCM0E2ODAxODY0OUFBMDYACgkQuzpoAYZJ
qgbSeRAAuBgoGYymbR0nMbPyutDsE9tCMMmctuFBDawaZiAHIPVfjDFdU+3V6OaF
dh/ykh5Pp0VvRAEnuNu8fgTPoTxTuAgmJNWb2FsrgNZDRYsnI0YaUWueFd3OxKpm
VVUX2HB7HrAWkhE0F+ABaXELuJ0isx/oJ4nND0lhnzVzpN23E5kH3m0g6cWwLBCQ
NLn0WhGUvHpr/pZzwjsVs4kTCPu4DtJJR1b48KJuzD1rrY1yY8bKS9Y+2NakaJZA
OClRJq1Dio+jZXvXQ4GOuddU1dolx0q2ZyFIqCeLEU3UCESn/N5zBHAoqQXXj47M
aMG9+RBQCF3hVvTHJPU8pAP88e2i8eIcUEcrU0pScxK43Rw82eGQnNwzY66TB0cS
mE5kwAFgDIAik58/MzTJKSwb4vbkpSgjtk8VW9u2Q4NG95DHxm3Yi1V/NcBStAkt
TgsjJ4d6GCeVHgcXOkp2Tkz3TX5/jHbVT3lukhzA3WavEeQBbBi0kIFoS27lBQmd
NdO52HOzzTSF5vUFCf5OMnUZKTjXdN85RpSXTAiPp0c2+kzIpyglhoaogQqP+d3M
laYMwLBdO9tMwwLQoXwTsaJflTPNlzrq+0hH+QA6o3zRj4U5v4fNUfYRohB/rzUU
S0aCD3cbPp1LmHZzBNnRJpY57Soq7Aiw8WfKFGstoQVVUFm8Ips=
=Jd2Q
-----END PGP SIGNATURE-----