CVE-2026-7017 Details
Description
HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets. When the server returns a 3xx redirect, `_maybe_redirect` follows the `Location:` header and `_prepare_headers_and_cb` re-merges the caller's `headers` argument into the new request, without checking whether the redirect target shares an origin with the original URL. Caller-supplied `Authorization`, `Cookie` and `Proxy-Authorization` headers are therefore re-sent to whatever host the redirect names, across scheme, host or port boundaries, and including `https` to `http` downgrades that expose them in plaintext on the wire. The HTTP::Tiny POD note that "Authorization headers will not be included in a redirected request" applied only to the URL-userinfo Basic-auth path, not to headers passed explicitly by the caller.
A vulnerability exists in HTTP::Tiny versions prior to 0.095 for Perl, where forward credential headers are sent to cross-origin redirect targets. This issue arises because the library follows 3xx redirects without verifying if the new location shares the same origin as the original URL. As a result, user-supplied Authorization, Cookie, and Proxy-Authorization headers are re-sent to the redirected host, potentially exposing sensitive information, especially during downgrades from https to http where data is transmitted in plaintext.
Users can update to HTTP::Tiny version 0.095 or later, where this vulnerability has been addressed. Instructions for updating can be found on the MetaCPAN HTTP::Tiny release page.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 7, 2026CISA-ADP
Assessed Jul 7, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/84984ef3930ddd4afcf5eb83b40d3cee200739c3.patch | CPANSec | Source CodeVendor |
| https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/8f32ca89e21c3ad0422adc698fa6ad17a193f55f.patch | CPANSec | Source CodeVendor |
| https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/e7a03aedf2395158f2b0d3bad2df943349227bb3.patch | CPANSec | Source CodeVendor |
| https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/pull/36 | CPANSec | Issue TrackingVendor |
| https://metacpan.org/release/HAARG/HTTP-Tiny-0.095-TRIAL/changes | CPANSec | Release NotesVendor |
| http://www.openwall.com/lists/oss-security/2026/07/07/13 | CVE |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-522 | Insufficiently Protected Credentials | CPANSec |
Affected Products
| Product | Versions |
|---|---|
| HTTP::Tiny | < 0.095 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 7, 2026 | CVE Modified | CVE |
| Jul 7, 2026 | New CVE Received | CPANSec |
| Jul 7, 2026 | CVE Modified | CISA-ADP |
Volerion