Junglewise Threat Intelligence

CVE-2026-7017: HAARG HTTP::Tiny credential leakage in cross-origin redirects

CVE-2026-7017 · Severity: high · CVSS 7.1 · Published 2026-07-07

Executive brief

A vulnerability in the HTTP::Tiny Perl library, which is used by applications to make web requests, can lead to the accidental exposure of sensitive credentials. When a web server redirects a request to a different website, the library may incorrectly forward authentication tokens and session cookies to that new destination. This could allow a malicious site to steal login credentials or session information from unsuspecting users or automated systems.

Technical details

HTTP::Tiny versions before 0.095 fail to verify origin boundaries during HTTP 3xx redirects. When a redirect is followed, the `_prepare_headers_and_cb` function re-merges caller-supplied headers—including 'Authorization', 'Cookie', and 'Proxy-Authorization'—into the new request regardless of whether the target host, port, or scheme matches the original. This behavior allows for credential leakage to cross-origin targets and can result in sensitive data being transmitted in plaintext if a redirect downgrades a connection from HTTPS to HTTP. The fix introduces header stripping for cross-origin redirects and disables HTTPS-to-HTTP downgrades by default.

Affected products

  • HAARG HTTP::Tiny < 0.095

Timeline

  • 2026-07-07: disclosed
  • 2026-07-07: advisory

References