Executive brief
A vulnerability in the HTTP::Tiny Perl library, which is used by applications to make web requests, can lead to the accidental exposure of sensitive credentials. When a web server redirects a request to a different website, the library may incorrectly forward authentication tokens and session cookies to that new destination. This could allow a malicious site to steal login credentials or session information from unsuspecting users or automated systems.
Technical details
HTTP::Tiny versions before 0.095 fail to verify origin boundaries during HTTP 3xx redirects. When a redirect is followed, the `_prepare_headers_and_cb` function re-merges caller-supplied headers—including 'Authorization', 'Cookie', and 'Proxy-Authorization'—into the new request regardless of whether the target host, port, or scheme matches the original. This behavior allows for credential leakage to cross-origin targets and can result in sensitive data being transmitted in plaintext if a redirect downgrades a connection from HTTPS to HTTP. The fix introduces header stripping for cross-origin redirects and disables HTTPS-to-HTTP downgrades by default.
Affected products
- HAARG HTTP::Tiny < 0.095
Timeline
- 2026-07-07: disclosed
- 2026-07-07: advisory
References
- https://cpan.org/modules
- https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/84984ef3930ddd4afcf5eb83b40d3cee200739c3.patch
- https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/8f32ca89e21c3ad0422adc698fa6ad17a193f55f.patch
- https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/e7a03aedf2395158f2b0d3bad2df943349227bb3.patch
- https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/pull/36
- https://metacpan.org/release/HAARG/HTTP-Tiny-0.095-TRIAL/changes