Critical Credential Leakage Vulnerabilities in libwww-perl Affect Fedora and Ubuntu

Critical Credential Leakage Vulnerabilities in libwww-perl Affect Fedora and Ubuntu

First seen 5 Jun 2026, 12:10 UTC Linuxsecurity 70% similarity 70.5

Article Content

Browse articles
ThreatCluster

Recent vulnerabilities in the libwww-perl library have been identified, affecting multiple Linux distributions including Fedora and Ubuntu. CVE-2026-8368, published on 2026-05-12, details a critical issue where Authorization headers could be leaked during cross-origin redirects. Fedora 43 has released a fix that strips these headers on such redirects to prevent credential leakage. Ubuntu's versions 26.04 LTS and earlier also face this exposure, allowing remote attackers to potentially access sensitive information. Users are advised to update their systems to the latest package versions to mitigate these risks. The vulnerabilities highlight the importance of secure handling of HTTP redirects in web applications. Both distributions have issued updates to address these issues, emphasizing the need for prompt action from system administrators.

Key Points: • CVE-2026-8368 exposes sensitive information via Authorization headers in redirects. • Fedora 43 and multiple Ubuntu versions are affected, necessitating urgent updates. • Mitigations include stripping sensitive headers and refusing insecure redirects.

ThreatCluster AI

Timeline

2026-05-12
CVE-2026-8368 published
A critical vulnerability in libwww-perl was disclosed, allowing credential leakage through redirects.
Linuxsecurity
2026-06-03
Ubuntu security notice USN-8378 released
Ubuntu announced a security issue in libwww-perl affecting multiple versions, urging users to update.
Linuxsecurity
2026-06-05
Fedora 43 update released
Fedora issued an update to libwww-perl, addressing the critical credential leakage vulnerability.
Linuxsecurity

Community

Browse all →

Tracked Entities in This Story