CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-7017

highCVSS 7.1covered by 2 sourcesfirst seen 2026-07-07
HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets. When the server returns a 3xx redirect, _maybe_redirect follows the Location: header and _prepare_headers_and_cb re-merges the caller's headers argument into the new request, without checking whether the redirect target shares an origin with the original URL. Caller-supplied Authorization, Cookie and Proxy-Authorization headers are therefore re-sent to whatever host the redirect names, across scheme, host or port boundaries, and including https to http downgrades that expose them in plaintext on the wire. The HTTP::Tiny POD note that "Authorization headers will not be included in a redirected request" applied only to the URL-userinfo Basic-auth path, not to headers passed explicitly by the caller.

CSIRTS triage

What
Multiple vulnerabilities including unsafe handling of Socket/pack functions leading to memory disclosure, regex matching errors, denial-of-service issues in file handling, and arbitrary code execution.
Who is affected
Systems running Perl with the affected functions in use, impacting a broad set of deployments.
Urgency
Multiple severity levels across the CVEs; RCE capability (CVE-2026-48962) requires immediate attention.
Action
Apply the Ubuntu security update USN-8684-1 or equivalent patches for your Perl installation.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-7017

Get an email if CVE-2026-7017 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-7017

CVE.org record

Embed the live status

CVE-2026-7017 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-7017 status](https://www.csirts.com/badge/CVE-2026-7017)](https://www.csirts.com/cve/CVE-2026-7017)