CVE-2011-0633: Gisle Aas Libwww-Perl

Medium severity, CVSS 4.3. EPSS: 4.2% chance of exploitation in the next 30 days.

The Net::HTTPS module in libwww-perl (LWP) before 6.00, as used in WWW::Mechanize, LWP::UserAgent, and other products, when running in environments that do not set the If-SSL-Cert-Subject header, does not enable full validation of SSL certificates by default, which allows remote attackers to spoof servers via man-in-the-middle (MITM) attacks involving hostnames that are not properly validated. NOTE: it could be argued that this is a design limitation of the Net::HTTPS API, and separate implementations should be independently assigned CVE identifiers for not working around this limitation. However, because this API was modified within LWP, a single CVE identifier has been assigned.

Affected products

  • Gisle Aas Libwww-Perl: version 0.01 only; version 0.02 only; version 0.03 only; version 0.04 only; version 5.00 only; version 5.01 only; …
  • Search.cpan Libwww-Perl: up to and including 5.837; version 5.40_01 only

Published 2011-05-13. Last modified 2026-06-16.