{"id":"openSUSE-SU-2026:20792-1","summary":"Security update for perl-HTTP-Tiny","details":"This update for perl-HTTP-Tiny fixes the following issues:\n\nChanges in perl-HTTP-Tiny:\n\n- updated to 0.094\n  0.094\n      - No changes from 0.093-TRIAL\n  0.093\n      - fix to prevent invalid characters in all headers, and prevent header\n        smuggling (CVE-2026-7010) bsc#1264992\n\n- updated to 0.092\n  0.092\n      - No changes from 0.091-TRIAL\n  0.091\n      [ADDED]\n      - Added keep_alive_timeout to force keepalive connections to be closed\n        based on a timeout.\n      [CHANGED]\n      - Optional tests are always required when releasing.\n      - Always use TCP_NODELAY option.\n      [FIXED]\n      - Fixed test incorrectly testing cookie jar interactions multiple times.\n      - Fixed perl version comparisons to work when not starting with 5.\n      - Fixed link to LIMITATIONS in documentation.\n\n- updated to 0.090\n  0.090\n      - No changes from 0.089-TRIAL\n  0.089\n      [CHANGED]\n      - Find the certificate bundle via IO::Socket::SSL rather than implementing\n        it in HTTP::Tiny.\n      - When encoding form data, given a hashref with an arrayref value,\n        preserve the order of the values in the arrayref rather than sorting.\n      [DOCS]\n      - Fixed internal link to \"TLS/SSL SUPPORT\" section\n","modified":"2026-05-26T08:15:05.295017993Z","published":"2026-05-25T09:05:33Z","related":["CVE-2026-7010"],"upstream":["CVE-2026-7010"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264992"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-7010"}],"schema_version":"1.7.5"}