CVE-2026-7010Disclosure

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values. The unvalidated inputs are the method and URI in the request line, the URL host that becomes the `Host:` header, and HTTP/1.1 control data field values. An attacker who controls one of these inputs, for example a user supplied URL passed to a webhook or URL fetch endpoint, can inject additional headers and smuggle requests to the upstream server.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-113

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-05-12); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-12: 1Mentions · 2026-05-15: 1Technical Details · 2026-05-12: 1Technical Details · 2026-05-15: 105-1205-15
Signal classification1 categories
Disclosure
2100.0%
Referenced assets3 URLs
Full discourse2 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    Perl CPAN CVE-2026-7010: HTTP::Tiny before 0.093 do not validate CRLF in HTTP request lines or control field header values https://www.openwall.com/lists/oss-security/2026/05/11/17 CVE-2026-8368: LWP::UserAgent before 6.83 leak [Proxy-]Authorization headers on cross-origin redirects https://www.openwall.com/lists/oss-security/2026/05/12/7

    Post summary

    The message lists two Perl module vulnerabilities with brief technical explanations but does not include PoCs, exploit tools, active exploitation claims, patches, or debunking statements.

    1000088
    4.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7010 HTTP Request Smuggling in Perl HTTP::Tiny Before Version 0.093 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7010

    Post summary

    The post announces CVE‑2026‑7010, a request-smuggling flaw in Perl's HTTP::Tiny module before v0.093, without indicating PoC, exploits, or available fixes.

    0000059
    4.0K followersView on X

Explore more