<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
	<DocumentTitle xml:lang="en">An update for perl-libwww-perl is now available for openEuler-22.03-LTS-SP4,openEuler-24.03-LTS,openEuler-24.03-LTS-SP1,openEuler-24.03-LTS-SP3,openEuler-20.03-LTS-SP4</DocumentTitle>
	<DocumentType>Security Advisory</DocumentType>
	<DocumentPublisher Type="Vendor">
		<ContactDetails>openeuler-security@openeuler.org</ContactDetails>
		<IssuingAuthority>openEuler security committee</IssuingAuthority>
	</DocumentPublisher>
	<DocumentTracking>
		<Identification>
			<ID>openEuler-SA-2026-2464</ID>
		</Identification>
		<Status>Final</Status>
		<Version>1.0</Version>
		<RevisionHistory>
			<Revision>
				<Number>1.0</Number>
				<Date>2026-05-29</Date>
				<Description>Initial</Description>
			</Revision>
		</RevisionHistory>
		<InitialReleaseDate>2026-05-29</InitialReleaseDate>
		<CurrentReleaseDate>2026-05-29</CurrentReleaseDate>
		<Generator>
			<Engine>openEuler SA Tool V1.0</Engine>
			<Date>2026-05-29</Date>
		</Generator>
	</DocumentTracking>
	<DocumentNotes>
		<Note Title="Synopsis" Type="General" Ordinal="1" xml:lang="en">perl-libwww-perl security update</Note>
		<Note Title="Summary" Type="General" Ordinal="2" xml:lang="en">An update for perl-libwww-perl is now available for openEuler-22.03-LTS-SP4,openEuler-24.03-LTS,openEuler-24.03-LTS-SP1,openEuler-24.03-LTS-SP3,openEuler-20.03-LTS-SP4</Note>
		<Note Title="Description" Type="General" Ordinal="3" xml:lang="en">The libwww-perl collection is a set of Perl modules which provides a simple and consistent application programming interface (API) to the World-Wide Web. The main focus of the library is to provide classes and functions that allow you to write WWW clients. The library also contain modules that are of more general use and even classes that help you implement simple HTTP servers.

Security Fix(es):

LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirects.

On a 3xx response, the redirect handler strips only Host and Cookie before issuing the follow-up request. Caller-supplied Authorization and Proxy-Authorization headers are sent unchanged to the redirect target, including across scheme, host, or port changes.

A redirect to an attacker controlled host therefore discloses the caller&apos;s credentials to that host.(CVE-2026-8368)</Note>
		<Note Title="Topic" Type="General" Ordinal="4" xml:lang="en">An update for perl-libwww-perl is now available for openEuler-22.03-LTS-SP4,openEuler-24.03-LTS,openEuler-24.03-LTS-SP1,openEuler-24.03-LTS-SP3,openEuler-20.03-LTS-SP4.

openEuler Security has rated this update as having a security impact of medium. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.</Note>
		<Note Title="Severity" Type="General" Ordinal="5" xml:lang="en">Medium</Note>
		<Note Title="Affected Component" Type="General" Ordinal="6" xml:lang="en">perl-libwww-perl</Note>
	</DocumentNotes>
	<DocumentReferences>
		<Reference Type="Self">
			<URL>https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2464</URL>
		</Reference>
		<Reference Type="openEuler CVE">
			<URL>https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8368</URL>
		</Reference>
		<Reference Type="Other">
			<URL>https://nvd.nist.gov/vuln/detail/CVE-2026-8368</URL>
		</Reference>
	</DocumentReferences>
	<ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
		<Branch Type="Product Name" Name="openEuler">
			<FullProductName ProductID="openEuler-22.03-LTS-SP4" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">openEuler-22.03-LTS-SP4</FullProductName>
			<FullProductName ProductID="openEuler-24.03-LTS" CPE="cpe:/a:openEuler:openEuler:24.03-LTS">openEuler-24.03-LTS</FullProductName>
			<FullProductName ProductID="openEuler-24.03-LTS-SP1" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP1">openEuler-24.03-LTS-SP1</FullProductName>
			<FullProductName ProductID="openEuler-24.03-LTS-SP3" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP3">openEuler-24.03-LTS-SP3</FullProductName>
			<FullProductName ProductID="openEuler-20.03-LTS-SP4" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP4">openEuler-20.03-LTS-SP4</FullProductName>
		</Branch>
		<Branch Type="Package Arch" Name="noarch">
			<FullProductName ProductID="perl-libwww-perl-6.66-2" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">perl-libwww-perl-6.66-2.oe2203sp4.noarch.rpm</FullProductName>
			<FullProductName ProductID="perl-libwww-perl-help-6.66-2" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">perl-libwww-perl-help-6.66-2.oe2203sp4.noarch.rpm</FullProductName>
			<FullProductName ProductID="perl-libwww-perl-6.67-2" CPE="cpe:/a:openEuler:openEuler:24.03-LTS">perl-libwww-perl-6.67-2.oe2403.noarch.rpm</FullProductName>
			<FullProductName ProductID="perl-libwww-perl-help-6.67-2" CPE="cpe:/a:openEuler:openEuler:24.03-LTS">perl-libwww-perl-help-6.67-2.oe2403.noarch.rpm</FullProductName>
			<FullProductName ProductID="perl-libwww-perl-6.67-2" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP1">perl-libwww-perl-6.67-2.oe2403sp1.noarch.rpm</FullProductName>
			<FullProductName ProductID="perl-libwww-perl-help-6.67-2" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP1">perl-libwww-perl-help-6.67-2.oe2403sp1.noarch.rpm</FullProductName>
			<FullProductName ProductID="perl-libwww-perl-6.67-2" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP3">perl-libwww-perl-6.67-2.oe2403sp3.noarch.rpm</FullProductName>
			<FullProductName ProductID="perl-libwww-perl-help-6.67-2" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP3">perl-libwww-perl-help-6.67-2.oe2403sp3.noarch.rpm</FullProductName>
			<FullProductName ProductID="perl-libwww-perl-6.46-2" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP4">perl-libwww-perl-6.46-2.oe2003sp4.noarch.rpm</FullProductName>
			<FullProductName ProductID="perl-libwww-perl-help-6.46-2" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP4">perl-libwww-perl-help-6.46-2.oe2003sp4.noarch.rpm</FullProductName>
		</Branch>
		<Branch Type="Package Arch" Name="src">
			<FullProductName ProductID="perl-libwww-perl-6.66-2" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">perl-libwww-perl-6.66-2.oe2203sp4.src.rpm</FullProductName>
			<FullProductName ProductID="perl-libwww-perl-6.67-2" CPE="cpe:/a:openEuler:openEuler:24.03-LTS">perl-libwww-perl-6.67-2.oe2403.src.rpm</FullProductName>
			<FullProductName ProductID="perl-libwww-perl-6.67-2" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP1">perl-libwww-perl-6.67-2.oe2403sp1.src.rpm</FullProductName>
			<FullProductName ProductID="perl-libwww-perl-6.67-2" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP3">perl-libwww-perl-6.67-2.oe2403sp3.src.rpm</FullProductName>
			<FullProductName ProductID="perl-libwww-perl-6.46-2" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP4">perl-libwww-perl-6.46-2.oe2003sp4.src.rpm</FullProductName>
		</Branch>
	</ProductTree>
	<Vulnerability Ordinal="1" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
		<Notes>
			<Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirects.

On a 3xx response, the redirect handler strips only Host and Cookie before issuing the follow-up request. Caller-supplied Authorization and Proxy-Authorization headers are sent unchanged to the redirect target, including across scheme, host, or port changes.

A redirect to an attacker controlled host therefore discloses the caller&apos;s credentials to that host.</Note>
		</Notes>
		<ReleaseDate>2026-05-29</ReleaseDate>
		<CVE>CVE-2026-8368</CVE>
		<ProductStatuses>
			<Status Type="Fixed">
				<ProductID>openEuler-22.03-LTS-SP4</ProductID>
				<ProductID>openEuler-24.03-LTS</ProductID>
				<ProductID>openEuler-24.03-LTS-SP1</ProductID>
				<ProductID>openEuler-24.03-LTS-SP3</ProductID>
				<ProductID>openEuler-20.03-LTS-SP4</ProductID>
			</Status>
		</ProductStatuses>
		<Threats>
			<Threat Type="Impact">
				<Description>Medium</Description>
			</Threat>
		</Threats>
		<CVSSScoreSets>
			<ScoreSet>
				<BaseScore>6.5</BaseScore>
				<Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</Vector>
			</ScoreSet>
		</CVSSScoreSets>
		<Remediations>
			<Remediation Type="Vendor Fix">
				<Description>perl-libwww-perl security update</Description>
				<DATE>2026-05-29</DATE>
				<URL>https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2464</URL>
			</Remediation>
		</Remediations>
	</Vulnerability>
</cvrfdoc>