Hi SRMers
libwww-perl in trixie is affected by CVE-2026-8368, where
LWP::UserAgent was leaking Authorization and Proxy-Authorization
headers on cross-origin redirects.
We did mark this issue as no-dsa, but it would be nice to include the
fix in 13.8.
The update was QA tested as well against reverse dependencies on
debusine in:
https://debusine.debian.net/debian/developers/work-request/1230930/
I added a followup upstream commit cherry-picked as well to further
harden to refuse https->http downgrade redirects by default.
Regards,
Salvatore