{"id":"openSUSE-SU-2026:21529-1","summary":"Security update for perl-HTTP-Tiny","details":"This update for perl-HTTP-Tiny fixes the following issues:\n\nChanges in perl-HTTP-Tiny:\n\n- updated to 0.096\n- CVE-2026-7017: Fixed forwarded credential headers to cross-origin redirect targets (bsc#1271020)\n- Caller-supplied Authorization, Cookie, and Proxy-Authorization\n  headers are now stripped on cross-origin redirects by default. Use\n  allow_credentialed_redirects to opt out.\n- Redirects are no longer automatically followed when going from https to http.\n  Use allow_downgrade to revert to the original behaviour.\n","modified":"2026-08-05T18:23:43.672800769Z","published":"2026-08-04T14:58:00Z","related":["CVE-2026-7017"],"upstream":["CVE-2026-7017"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271020"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-7017"}],"affected":[{"package":{"name":"perl-HTTP-Tiny","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/perl-HTTP-Tiny&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.096-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"perl-HTTP-Tiny":"0.096-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21529-1.json"}}],"schema_version":"1.8.0"}