Bug 2476481 - perl-libwww-perl-6.83 is available
Summary: perl-libwww-perl-6.83 is available
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: perl-libwww-perl
Version: rawhide
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Michal Josef Spacek
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-05-12 14:48 UTC by Upstream Release Monitoring
Modified: 2026-05-31 00:55 UTC (History)
4 users (show)

Fixed In Version: perl-libwww-perl-6.83-1.fc44
Clone Of:
Environment:
Last Closed: 2026-05-31 00:55:21 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Upstream Release Monitoring 2026-05-12 14:48:54 UTC
Releases retrieved: 6.83
Upstream release that is considered latest: 6.83
Current version/release in rawhide: 6.82-1.fc45
URL: https://metacpan.org/dist/libwww-perl/

Please consult the package updates policy before you issue an update to a stable branch: https://docs.fedoraproject.org/en-US/fesco/Updates_Policy/


More information about the service that created this bug can be found at: https://docs.fedoraproject.org/en-US/package-maintainers/Upstream_Release_Monitoring


Please keep in mind that with any upstream change, there may also be packaging changes that need to be made. Specifically, please remember that it is your responsibility to review the new version to ensure that the licensing is still correct and that no non-free or legally problematic items have been added upstream.


Based on the information from Anitya: https://release-monitoring.org/project/3024/


To change the monitoring settings for the project, please visit:
https://src.fedoraproject.org/rpms/perl-libwww-perl

Comment 1 Michal Josef Spacek 2026-05-19 14:51:44 UTC
6.83      2026-05-12 11:41:48Z
    - LWP::UserAgent now strips Authorization and Proxy-Authorization headers
      on cross-origin redirects (a different scheme, host, or port) to prevent
      credential leakage to the redirect target. Same-origin redirects retain
      credentials. Opt out with allow_credentialed_redirects => 1.
      CVE-2026-8368 reported by Kai Zen; PoC and initial patch by Stig
      Palmquist.
    - LWP::UserAgent now refuses https to http redirects by default to prevent
      leaking remaining request headers and bodies over plaintext. Opt in with
      allow_downgrade => 1. Related hardening alongside CVE-2026-8368; PoC by
      Stig Palmquist.


For Fedora Rawhide, F44 and F43

Comment 2 Fedora Update System 2026-05-20 20:42:01 UTC
FEDORA-2026-8d1333fb52 (perl-libwww-perl-6.83-1.fc44) has been submitted as an update to Fedora 44.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-8d1333fb52

Comment 3 Fedora Update System 2026-05-21 02:35:34 UTC
FEDORA-2026-8d1333fb52 has been pushed to the Fedora 44 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-8d1333fb52`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-8d1333fb52

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 4 Fedora Update System 2026-05-31 00:55:21 UTC
FEDORA-2026-8d1333fb52 (perl-libwww-perl-6.83-1.fc44) has been pushed to the Fedora 44 stable repository.
If problem still persists, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.