PT-2026-39866 · Cpan · Tiny-Http

·

CVE-2026-7010

·

Published

2026-05-11

·

Updated

2026-08-25

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions HTTP::Tiny versions prior to 0.093
Description Perl HTTP::Tiny fails to validate CRLF (Carriage Return Line Feed) sequences in HTTP request lines or control field header values. The issue involves unvalidated inputs including the method and URI in the request line, the URL host used for the "Host:" header, and HTTP/1.1 control data field values. An attacker controlling these inputs, such as through a user-supplied URL in a webhook or URL fetch endpoint, can inject additional headers and smuggle requests to the upstream server.
Recommendations Update to version 0.093 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-7010
ECHO-8F6A-4267-55C4
OESA-2026-2371
OESA-2026-2372
OESA-2026-2373
OESA-2026-2374
OESA-2026-2520
OPENSUSE-SU-2026:10805-1
OPENSUSE-SU-2026:20792-1

Affected Products

Tiny-Http