Debian Patches
Status for libhttp-tiny-perl/0.090-1+deb13u1
| Patch | Description | Author | Forwarded | Bugs | Origin | Last update |
|---|---|---|---|---|---|---|
| CVE-2026-7017-4.diff | demonstrate that https upgrade now strips credentials as it is a change of origin (Backported for Debian by Niko Tyni) |
Olaf Alders <olaf@wundersolutions.com> | yes | debian upstream | backport, https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/0d7b31e7a16281e918e68fad855ddf249209b026 | 2026-05-14 |
| tests-internet.patch | run new test which needs internet access only conditionally | gregor herrmann <gregoa@debian.org> | not-needed | vendor | 2016-08-29 | |
| CVE-2026-7010-tests.diff | CVE-2026-7010: add tests (Backported for Debian by Niko Tyni) |
Stig Palmquist <git@stig.io> | yes | debian upstream | backport, https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/207890b6dab21c9db314af50d63202d13f317e2a | 2026-04-27 |
| CVE-2026-7010.diff | CVE-2026-7010: fix for request / header smuggling Validate control headers, request uri and request method for characters that could be used in request smuggling or header injection attacks. (Backported for Debian by Niko Tyni) |
Stig <stig@stig.io> | yes | debian upstream | backport, https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/d73c7651e82ace02693842df55928b6c3ae7c38d | 2026-04-27 |
| CVE-2026-7017-1.diff | refuse https to http redirects by default Allow opt in via allow_downgrade (Backported for Debian by Niko Tyni) |
Olaf Alders <olaf@wundersolutions.com> | yes | debian upstream | backport, https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/84984ef3930ddd4afcf5eb83b40d3cee200739c3 | 2026-05-14 |
| CVE-2026-7017-2.diff | strip auth headers on cross-origin redirects (Backported for Debian by Niko Tyni) |
Olaf Alders <olaf@wundersolutions.com> | yes | debian upstream | backport, https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/e7a03aedf2395158f2b0d3bad2df943349227bb3 | 2026-05-14 |
| CVE-2026-7017-3.diff | Fix protocol-relative Location handling so it can't be used to bypass credential strip (Backported for Debian by Niko Tyni) |
Olaf Alders <olaf@wundersolutions.com> | yes | debian upstream | backport, https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/8f32ca89e21c3ad0422adc698fa6ad17a193f55f | 2026-05-14 |
| CVE-2026-7017-5.diff | Add tests to cover redirects from requests providing basic auth via the URL rather than a manually set Authorization header, with and without the allow_credentialed_redirects option. (Backported for Debian by Niko Tyni) |
Olaf Alders <olaf@wundersolutions.com> | yes | debian upstream | backport, https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/d9aa62b0013abb790b3cf45340320fae475ffdb2 | 2026-05-15 |
All known versions for source package 'libhttp-tiny-perl'
- 0.096-1 (sid, forky)
- 0.090-1+deb13u1 (trixie-proposed-updates)
- 0.090-1 (trixie)
- 0.082-2 (bookworm)
