Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-7017— HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets

AI Predicted 7.4 Difficulty: Easy EPSS 0.26% · P17

Possible ATT&CK Techniques 1AI

T1059.019

Affected Version Matrix 1

VendorProductVersion RangeStatus
HAARGHTTP::Tiny< 0.095affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-7017

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets
Source: CVE Program / CVE List V5
Vulnerability Description
HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets. When the server returns a 3xx redirect, `_maybe_redirect` follows the `Location:` header and `_prepare_headers_and_cb` re-merges the caller's `headers` argument into the new request, without checking whether the redirect target shares an origin with the original URL. Caller-supplied `Authorization`, `Cookie` and `Proxy-Authorization` headers are therefore re-sent to whatever host the redirect names, across scheme, host or port boundaries, and including `https` to `http` downgrades that expose them in plaintext on the wire. The HTTP::Tiny POD note that "Authorization headers will not be included in a redirected request" applied only to the URL-userinfo Basic-auth path, not to headers passed explicitly by the caller.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
不充分的凭证保护机制
Source: CVE Program / CVE List V5
Vulnerability Title
HAARG HTTP-Tiny 信任管理问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
HAARG HTTP::Tiny是HAARG的Perl HTTP客户端库。 HAARG HTTP-Tiny 0.095之前版本存在信任管理问题漏洞,该漏洞源于未检查重定向目标是否与原始URL同源,导致调用者提供的Authorization、Cookie和Proxy-Authorization标头被转发到跨域重定向目标。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
HAARGHTTP::Tiny 0 ~ 0.095 -

II. Public POCs for CVE-2026-7017

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-7017

登录查看更多情报信息。

Patches & Fixes for CVE-2026-7017 (4)

News Coverage for CVE-2026-7017 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-7017

No comments yet


Leave a comment