CVE-2026-8368
MEDIUMLWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirects
Title source: cnaDescription
LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirects. On a 3xx response, the redirect handler strips only Host and Cookie before issuing the follow-up request. Caller-supplied Authorization and Proxy-Authorization headers are sent unchanged to the redirect target, including across scheme, host, or port changes. A redirect to an attacker controlled host therefore discloses the caller's credentials to that host.
References (5)
Core 5
Core References
Patch patch
https://github.com/libwww-perl/libwww-perl/commit/9c4aeb6f2dd32f2b7eaf2d7827cade31ea6cb2c6.patch
Release Notes release-notes
https://metacpan.org/release/OALDERS/libwww-perl-6.83/changes
Issue Tracking issue-tracking
https://github.com/libwww-perl/libwww-perl/pull/512
Related related
https://github.com/libwww-perl/libwww-perl/pull/284
Scores
CVSS v3
6.5
EPSS
0.0027
EPSS Percentile
17.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-522
Status
published
Products (1)
OALDERS/LWP::UserAgent
< 6.83
Published
May 12, 2026
Tracked Since
May 12, 2026