OESA-2026-2464

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2026-2464
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2026-2464.json
JSON Data
https://api.test.osv.dev/v1/vulns/OESA-2026-2464
Upstream
Published
2026-05-29T13:33:16Z
Modified
2026-05-29T13:45:08.561724511Z
Summary
perl-libwww-perl security update
Details

The libwww-perl collection is a set of Perl modules which provides a simple and consistent application programming interface (API) to the World-Wide Web. The main focus of the library is to provide classes and functions that allow you to write WWW clients. The library also contain modules that are of more general use and even classes that help you implement simple HTTP servers.

Security Fix(es):

LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirects.

On a 3xx response, the redirect handler strips only Host and Cookie before issuing the follow-up request. Caller-supplied Authorization and Proxy-Authorization headers are sent unchanged to the redirect target, including across scheme, host, or port changes.

A redirect to an attacker controlled host therefore discloses the caller's credentials to that host.(CVE-2026-8368)

Database specific
{
    "severity": "Medium"
}
References

Affected packages

openEuler:20.03-LTS-SP4
perl-libwww-perl

Package

Name
perl-libwww-perl
Purl
pkg:rpm/openEuler/perl-libwww-perl&distro=openEuler-20.03-LTS-SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.46-2.oe2003sp4

Ecosystem specific

{
    "noarch": [
        "perl-libwww-perl-6.46-2.oe2003sp4.noarch.rpm",
        "perl-libwww-perl-help-6.46-2.oe2003sp4.noarch.rpm"
    ],
    "src": [
        "perl-libwww-perl-6.46-2.oe2003sp4.src.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-2464.json"
openEuler:22.03-LTS-SP4
perl-libwww-perl

Package

Name
perl-libwww-perl
Purl
pkg:rpm/openEuler/perl-libwww-perl&distro=openEuler-22.03-LTS-SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.66-2.oe2203sp4

Ecosystem specific

{
    "noarch": [
        "perl-libwww-perl-6.66-2.oe2203sp4.noarch.rpm",
        "perl-libwww-perl-help-6.66-2.oe2203sp4.noarch.rpm"
    ],
    "src": [
        "perl-libwww-perl-6.66-2.oe2203sp4.src.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-2464.json"
openEuler:24.03-LTS
perl-libwww-perl

Package

Name
perl-libwww-perl
Purl
pkg:rpm/openEuler/perl-libwww-perl&distro=openEuler-24.03-LTS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.67-2.oe2403sp3

Ecosystem specific

{
    "noarch": [
        "perl-libwww-perl-6.67-2.oe2403.noarch.rpm",
        "perl-libwww-perl-help-6.67-2.oe2403.noarch.rpm",
        "perl-libwww-perl-6.67-2.oe2403sp1.noarch.rpm",
        "perl-libwww-perl-help-6.67-2.oe2403sp1.noarch.rpm",
        "perl-libwww-perl-6.67-2.oe2403sp3.noarch.rpm",
        "perl-libwww-perl-help-6.67-2.oe2403sp3.noarch.rpm"
    ],
    "src": [
        "perl-libwww-perl-6.67-2.oe2403.src.rpm",
        "perl-libwww-perl-6.67-2.oe2403sp1.src.rpm",
        "perl-libwww-perl-6.67-2.oe2403sp3.src.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-2464.json"
openEuler:24.03-LTS-SP1
perl-libwww-perl

Package

Name
perl-libwww-perl
Purl
pkg:rpm/openEuler/perl-libwww-perl&distro=openEuler-24.03-LTS-SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.67-2.oe2403sp1

Ecosystem specific

{
    "noarch": [
        "perl-libwww-perl-6.67-2.oe2403sp1.noarch.rpm",
        "perl-libwww-perl-help-6.67-2.oe2403sp1.noarch.rpm"
    ],
    "src": [
        "perl-libwww-perl-6.67-2.oe2403sp1.src.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-2464.json"
openEuler:24.03-LTS-SP3
perl-libwww-perl

Package

Name
perl-libwww-perl
Purl
pkg:rpm/openEuler/perl-libwww-perl&distro=openEuler-24.03-LTS-SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.67-2.oe2403sp3

Ecosystem specific

{
    "noarch": [
        "perl-libwww-perl-6.67-2.oe2403sp3.noarch.rpm",
        "perl-libwww-perl-help-6.67-2.oe2403sp3.noarch.rpm"
    ],
    "src": [
        "perl-libwww-perl-6.67-2.oe2403sp3.src.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-2464.json"