CVE-2023-31486: Http::tiny Project Http::tiny
High severity, CVSS 8.1. EPSS: 1.7% chance of exploitation in the next 30 days.
HTTP::Tiny before 0.083, a Perl core module since 5.13.9 and available standalone on CPAN, has an insecure default TLS configuration where users must opt in to verify certificates.
Affected products
- Http::tiny Project Http::tiny: before 0.083 (fixed in 0.083)
- Perl Perl: before 5.38.0 (fixed in 5.38.0)
Published 2023-04-29. Last modified 2026-06-17.