
Perl CPAN CVE-2026-7010: HTTP::Tiny before 0.093 do not validate CRLF in HTTP request lines or control field header values https://www.openwall.com/lists/oss-security/2026/05/11/17 CVE-2026-8368: LWP::UserAgent before 6.83 leak [Proxy-]Authorization headers on cross-origin redirects https://www.openwall.com/lists/oss-security/2026/05/12/7
Post summary
The text discloses two Perl module CVEs, detailing CRLF validation failure in HTTP::Tiny and Authorization header leakage in LWP::UserAgent.

