High severity8.1NVD Advisory· Published Apr 29, 2023· Updated Jun 17, 2026
CVE-2023-31486
CVE-2023-31486
Description
HTTP::Tiny before 0.083, a Perl core module since 5.13.9 and available standalone on CPAN, has an insecure default TLS configuration where users must opt in to verify certificates.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
10- HTTP::Tiny/HTTP::Tinydescription
- Range: <0.083
- osv-coords6 versionspkg:rpm/almalinux/perl-HTTP-Tinypkg:rpm/opensuse/perl-HTTP-Tiny&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/perl-HTTP-Tiny&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/perl-HTTP-Tiny&distro=openSUSE%20Tumbleweedpkg:rpm/suse/perl-HTTP-Tiny&distro=SUSE%20Package%20Hub%2015%20SP4pkg:rpm/suse/perl-HTTP-Tiny&distro=SUSE%20Package%20Hub%2015%20SP5
< 0.076-461.el9+ 5 more
- (no CPE)range: < 0.076-461.el9
- (no CPE)range: < 0.086-bp154.2.3.1
- (no CPE)range: < 0.086-bp155.3.3.1
- (no CPE)range: < 0.086-1.1
- (no CPE)range: < 0.086-bp154.2.3.1
- (no CPE)range: < 0.086-bp155.3.3.1
Patches
Vulnerability mechanics
References
11- www.openwall.com/lists/oss-security/2023/04/29/1nvdMailing ListPatch
- www.openwall.com/lists/oss-security/2023/05/03/3nvdMailing ListPatch
- blog.hackeriet.no/perl-http-tiny-insecure-tls-default-affects-cpan-modules/nvdMitigationPatchThird Party Advisory
- github.com/chansen/p5-http-tiny/pull/153nvdPatch
- www.openwall.com/lists/oss-security/2023/04/18/14nvdMailing ListPatch
- www.openwall.com/lists/oss-security/2023/05/07/2nvdMailing ListThird Party Advisory
- www.openwall.com/lists/oss-security/2023/05/03/4nvdMailing ListThird Party Advisory
- www.openwall.com/lists/oss-security/2023/05/03/5nvdMailing List
- hackeriet.github.io/cpan-http-tiny-overview/nvdProduct
- www.reddit.com/r/perl/comments/111tadi/psa_httptiny_disabled_ssl_verification_by_default/nvdIssue Tracking
- security.netapp.com/advisory/ntap-20241129-0011/nvd
News mentions
0No linked articles in our index yet.