Amazon Linux 2023 Security Advisory: ALAS2023-2026-1764
Advisory Released Date: 2026-06-08
Advisory Updated Date: 2026-06-08
Severity:
Medium
Issue Overview:
LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirects.
On a 3xx response, the redirect handler strips only Host and Cookie before issuing the follow-up request. Caller-supplied Authorization and Proxy-Authorization headers are sent unchanged to the redirect target, including across scheme, host, or port changes.
A redirect to an attacker controlled host therefore discloses the caller's credentials to that host. (CVE-2026-8368)
Affected Packages:
perl-libwww-perl
Issue Correction:
Run dnf update perl-libwww-perl --releasever 2023.12.20260608 or dnf update --advisory ALAS2023-2026-1764 --releasever 2023.12.20260608 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation
New Packages:
noarch:
perl-libwww-perl-tests-6.58-1.amzn2023.0.3.noarch
perl-libwww-perl-6.58-1.amzn2023.0.3.noarch
src:
perl-libwww-perl-6.58-1.amzn2023.0.3.src