Debian Patches

Status for libhttp-tiny-perl/0.090-1+deb13u1

Patch Description Author Forwarded Bugs Origin Last update
CVE-2026-7017-4.diff demonstrate that https upgrade now strips credentials
as it is a change of origin

(Backported for Debian by Niko Tyni)
Olaf Alders <olaf@wundersolutions.com> yes debian upstream backport, https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/0d7b31e7a16281e918e68fad855ddf249209b026 2026-05-14
tests-internet.patch run new test which needs internet access only conditionally gregor herrmann <gregoa@debian.org> not-needed vendor 2016-08-29
CVE-2026-7010-tests.diff CVE-2026-7010: add tests
(Backported for Debian by Niko Tyni)
Stig Palmquist <git@stig.io> yes debian upstream backport, https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/207890b6dab21c9db314af50d63202d13f317e2a 2026-04-27
CVE-2026-7010.diff CVE-2026-7010: fix for request / header smuggling
Validate control headers, request uri and request method for characters
that could be used in request smuggling or header injection attacks.

(Backported for Debian by Niko Tyni)
Stig <stig@stig.io> yes debian upstream backport, https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/d73c7651e82ace02693842df55928b6c3ae7c38d 2026-04-27
CVE-2026-7017-1.diff refuse https to http redirects by default
Allow opt in via allow_downgrade

(Backported for Debian by Niko Tyni)
Olaf Alders <olaf@wundersolutions.com> yes debian upstream backport, https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/84984ef3930ddd4afcf5eb83b40d3cee200739c3 2026-05-14
CVE-2026-7017-2.diff strip auth headers on cross-origin redirects
(Backported for Debian by Niko Tyni)
Olaf Alders <olaf@wundersolutions.com> yes debian upstream backport, https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/e7a03aedf2395158f2b0d3bad2df943349227bb3 2026-05-14
CVE-2026-7017-3.diff Fix protocol-relative Location handling so it can't be used to bypass credential strip

(Backported for Debian by Niko Tyni)
Olaf Alders <olaf@wundersolutions.com> yes debian upstream backport, https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/8f32ca89e21c3ad0422adc698fa6ad17a193f55f 2026-05-14
CVE-2026-7017-5.diff Add tests to cover redirects from requests providing basic auth via the URL

rather than a manually set Authorization header, with and without the
allow_credentialed_redirects option.

(Backported for Debian by Niko Tyni)
Olaf Alders <olaf@wundersolutions.com> yes debian upstream backport, https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/d9aa62b0013abb790b3cf45340320fae475ffdb2 2026-05-15

All known versions for source package 'libhttp-tiny-perl'

Links