ALAS2-2026-3325


Amazon Linux 2 Security Advisory: ALAS2-2026-3325
Advisory Released Date: 2026-06-08
Advisory Updated Date: 2026-06-08
Severity: Medium

Issue Overview:

LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirects.

On a 3xx response, the redirect handler strips only Host and Cookie before issuing the follow-up request. Caller-supplied Authorization and Proxy-Authorization headers are sent unchanged to the redirect target, including across scheme, host, or port changes.

A redirect to an attacker controlled host therefore discloses the caller's credentials to that host. (CVE-2026-8368)


Affected Packages:

perl-libwww-perl


Note:

This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.


Issue Correction:
Run yum update perl-libwww-perl or yum update --advisory ALAS2-2026-3325 to update your system.

New Packages:
noarch:
    perl-libwww-perl-6.05-2.amzn2.0.1.noarch

src:
    perl-libwww-perl-6.05-2.amzn2.0.1.src