Junglewise Threat Intelligence

CVE-2026-8368: libwww-perl LWP::UserAgent credential leak on cross-origin redirects

CVE-2026-8368 · Severity: medium · CVSS 6.5 · Published 2026-05-12

Executive brief

A vulnerability in a popular Perl web library could allow attackers to steal sensitive login credentials. When the library follows a link that redirects to a different website, it fails to remove security tokens and passwords from the request. An attacker who controls a website can use this to trick the library into sending them a user's private authentication data.

Technical details

LWP::UserAgent in libwww-perl versions prior to 6.83 contains a credential leak vulnerability (CWE-522). When handling HTTP 3xx redirects, the library's redirect handler only strips 'Host' and 'Cookie' headers before issuing the follow-up request. If a request is redirected to a different origin (different scheme, host, or port), caller-supplied 'Authorization' and 'Proxy-Authorization' headers are forwarded unchanged. An attacker can exploit this by inducing a redirect to a malicious server to capture these credentials. The issue is fixed in version 6.83, which now strips these headers on cross-origin redirects unless the 'allow_credentialed_redirects' option is explicitly enabled.

Affected products

  • libwww-perl project libwww-perl < 6.83

Timeline

  • 2026-05-11: disclosed: Issue reported to maintainers.
  • 2026-05-12: patched: libwww-perl 6.83 released.
  • 2026-05-12: advisory: Public disclosure of CVE-2026-8368.

References