SUSE alert openSUSE-SU-2026:0191-1 (perl-HTTP-Tiny)
| From: | maintenance@opensuse.org | |
| To: | security-announce@lists.opensuse.org | |
| Subject: | openSUSE-SU-2026:0191-1: moderate: Security update for perl-HTTP-Tiny | |
| Date: | Fri, 05 Jun 2026 18:05:44 +0200 | |
| Message-ID: | <20260605160544.28304FCE4@maintenance.suse.de> | |
| Archive-link: | Article |
openSUSE Security Update: Security update for perl-HTTP-Tiny ______________________________________________________________________________ Announcement ID: openSUSE-SU-2026:0191-1 Rating: moderate References: #1264992 Cross-References: CVE-2026-7010 Affected Products: openSUSE Backports SLE-15-SP7 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for perl-HTTP-Tiny fixes the following issues: - updated to 0.094 0.094 2026-05-17 10:31:00+02:00 Europe/Brussels - No changes from 0.093-TRIAL 0.093 2026-05-11 17:18:12+02:00 Europe/Brussels (TRIAL RELEASE) - fix to prevent invalid characters in all headers, and prevent header smuggling (CVE-2026-7010) boo#1264992 - updated to 0.092 0.092 2025-12-27 20:49:41+01:00 Europe/Berlin - No changes from 0.091-TRIAL 0.091 2025-12-13 06:26:51+01:00 Europe/Brussels (TRIAL RELEASE) [ADDED] - Added keep_alive_timeout to force keepalive connections to be closed based on a timeout. [CHANGED] - Optional tests are always required when releasing. - Always use TCP_NODELAY option. [FIXED] - Fixed test incorrectly testing cookie jar interactions multiple times. - Fixed perl version comparisons to work when not starting with 5. - Fixed link to LIMITATIONS in documentation. - updated to 0.090 0.090 2024-11-12 11:51:32+01:00 Europe/Brussels - No changes from 0.089-TRIAL 0.089 2024-10-21 09:35:48+02:00 Europe/Brussels (TRIAL RELEASE) [CHANGED] - Find the certificate bundle via IO::Socket::SSL rather than implementing it in HTTP::Tiny. - When encoding form data, given a hashref with an arrayref value, preserve the order of the values in the arrayref rather than sorting. [DOCS] - Fixed internal link to "TLS/SSL SUPPORT" section - Fix disabling of __perllib_provides - updated to 0.088 0.088 2023-07-11 08:52:54-04:00 America/New_York [DOCS] - Update metadata to point to new Perl-Toolchain-Gang repository. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP7: zypper in -t patch openSUSE-2026-191=1 Package List: - openSUSE Backports SLE-15-SP7 (noarch): perl-HTTP-Tiny-0.094-bp157.2.3.1 References: https://www.suse.com/security/cve/CVE-2026-7010.html https://bugzilla.suse.com/1264992
