CVE-2026-8368Disclosure

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirects. On a 3xx response, the redirect handler strips only Host and Cookie before issuing the follow-up request. Caller-supplied Authorization and Proxy-Authorization headers are sent unchanged to the redirect target, including across scheme, host, or port changes. A redirect to an attacker controlled host therefore discloses the caller's credentials to that host.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-522

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-05-15); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-15: 1Mentions · 2026-06-03: 1Patch / Workaround · 2026-06-03: 1Technical Details · 2026-05-15: 1Technical Details · 2026-06-03: 105-1506-03
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-151
Disclosure1
2026-06-031
Patch1
Full discourse2 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    Perl CPAN CVE-2026-7010: HTTP::Tiny before 0.093 do not validate CRLF in HTTP request lines or control field header values https://www.openwall.com/lists/oss-security/2026/05/11/17 CVE-2026-8368: LWP::UserAgent before 6.83 leak [Proxy-]Authorization headers on cross-origin redirects https://www.openwall.com/lists/oss-security/2026/05/12/7

    Post summary

    The text discloses two Perl module CVEs, detailing CRLF validation failure in HTTP::Tiny and Authorization header leakage in LWP::UserAgent.

    1000088
    4.6K followersView on X
  • WindowsForum@windowsforum
    Patch

    🪟 Microsoft added a Fix Guide for a Perl LWP::UserAgent redirect credential leak (CVE-2026-8368). Not flashy, but it’s the “oops we sent secrets to http://evil.com” classic. Update Perl. https://windowsforum.com/threads/cve-2026-8368-perl-lwp-useragent-credential-leaks-via-redirects-fix-guide.422034/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #MicrosoftSecurityUpdateGuide #Cve20268368 #PerlLwpUseragent https://t.co/WwrVLapsmr

    Post summary

    Microsoft released a fix guide to patch a credential‑leak vulnerability in Perl’s LWP::UserAgent; no PoC, exploit, or active exploitation claims are present.

    0000038
    1.1K followersView on X

Explore more