Amazon Linux 2 Security Advisory: ALAS2-2026-3325
Advisory Released Date: 2026-06-08
Advisory Updated Date: 2026-06-08
LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirects.
On a 3xx response, the redirect handler strips only Host and Cookie before issuing the follow-up request. Caller-supplied Authorization and Proxy-Authorization headers are sent unchanged to the redirect target, including across scheme, host, or port changes.
A redirect to an attacker controlled host therefore discloses the caller's credentials to that host. (CVE-2026-8368)
Affected Packages:
perl-libwww-perl
Note:
This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.
Issue Correction:
Run yum update perl-libwww-perl or yum update --advisory ALAS2-2026-3325 to update your system.
noarch:
perl-libwww-perl-6.05-2.amzn2.0.1.noarch
src:
perl-libwww-perl-6.05-2.amzn2.0.1.src