Executive brief
A vulnerability in a popular Perl web library could allow attackers to steal sensitive login credentials. When the library follows a link that redirects to a different website, it fails to remove security tokens and passwords from the request. An attacker who controls a website can use this to trick the library into sending them a user's private authentication data.
Technical details
LWP::UserAgent in libwww-perl versions prior to 6.83 contains a credential leak vulnerability (CWE-522). When handling HTTP 3xx redirects, the library's redirect handler only strips 'Host' and 'Cookie' headers before issuing the follow-up request. If a request is redirected to a different origin (different scheme, host, or port), caller-supplied 'Authorization' and 'Proxy-Authorization' headers are forwarded unchanged. An attacker can exploit this by inducing a redirect to a malicious server to capture these credentials. The issue is fixed in version 6.83, which now strips these headers on cross-origin redirects unless the 'allow_credentialed_redirects' option is explicitly enabled.
Affected products
- libwww-perl project libwww-perl < 6.83
Timeline
- 2026-05-11: disclosed: Issue reported to maintainers.
- 2026-05-12: patched: libwww-perl 6.83 released.
- 2026-05-12: advisory: Public disclosure of CVE-2026-8368.
References
- https://github.com/libwww-perl/libwww-perl/commit/9c4aeb6f2dd32f2b7eaf2d7827cade31ea6cb2c6.patch
- https://github.com/libwww-perl/libwww-perl/pull/284
- https://github.com/libwww-perl/libwww-perl/pull/512
- https://metacpan.org/release/OALDERS/libwww-perl-6.83/changes
- http://www.openwall.com/lists/oss-security/2026/05/12/7