#1147175 trixie-pu: package libwww-perl/6.78-1+deb13u1

#1147175#5
Date:
2026-09-08 19:39:28 UTC
From:
To:
Hi SRMers

libwww-perl in trixie is affected by CVE-2026-8368, where
LWP::UserAgent was leaking Authorization and Proxy-Authorization
headers on cross-origin redirects.

We did mark this issue as no-dsa, but it would be nice to include the
fix in 13.8.

The update was QA tested as well against reverse dependencies on
debusine in:
https://debusine.debian.net/debian/developers/work-request/1230930/

I added a followup upstream commit cherry-picked as well to further
harden to refuse https->http downgrade redirects by default.

Regards,
Salvatore