Back

MEDIUM

HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values

Published May 11, 2026

Description

HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values.

The unvalidated inputs are the method and URI in the request line, the URL host that becomes the `Host:` header, and HTTP/1.1 control data field values.

An attacker who controls one of these inputs, for example a user supplied URL passed to a webhook or URL fetch endpoint, can inject additional headers and smuggle requests to the upstream server.

Affected products

Remediation

Vendor solution

Upgrade to HTTP-Tiny 0.093-TRIAL or later.

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner CPANSec
Published May 11, 2026
Updated May 12, 2026
Reserved Apr 25, 2026
CISA Vulnrichment
Updated May 12, 2026
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a