Cpp-Httplib

Yhirose · 24 CVEs

CVE-2026-77358
HIGH

cpp-httplib: Use-after-free of TLS session in WebSocketClient::shutdown_and_close()

Aug 27, 2026

CVE-2026-77341
MEDIUM

cpp-httplib: CRLF injection via unvalidated HTTP trailer headers in chunked response writing

Aug 27, 2026

CVE-2026-54919
HIGH

cpp-httplib: TLS certificate chain verification bypassed for IP-literal hosts on Mbed TLS and wolfSSL backends

Jul 10, 2026

CVE-2026-45372
CRITICAL

cpp-httplib: HTTP header value percent-decoding in server-side `parse_header` enables CRLF injection

May 29, 2026

CVE-2026-46527
HIGH

cpp-httplib: Malicious `X-Forwarded-For` Under Trusted-Proxy Configuration Triggers Empty `vector::front()`, Leading to…

May 29, 2026

CVE-2026-45352
HIGH

cpp-httplib DoS: Negative chunk-size in chunked Transfer-Encoding

May 29, 2026

CVE-2026-34441
MEDIUM

cpp-httplib: HTTP Request Smuggling via Unconsumed GET Request Body

Mar 31, 2026

CVE-2026-33745
HIGH

cpp-httplib Client Leaks Authentication Credentials to Untrusted Hosts on Cross-Origin HTTP Redirect

Mar 27, 2026

CVE-2026-32627
HIGH

cpp-httplib has a Silent TLS Certificate Verification Bypass on HTTPS Redirect via Proxy

Mar 13, 2026

CVE-2026-31870
HIGH

cpp-httplib Affected by Remote Process Crash via Malformed Content-Length Response Header

Mar 11, 2026

CVE-2026-29076
MEDIUM

cpp-httplib: Stack Overflow Denial of Service (DoS) via std::regex in multipart filename parsing

Mar 7, 2026

CVE-2026-28435
HIGH

Payload size limit bypass via gzip decompression in ContentReader (streaming) allows oversized request bodies in cpp-ht…

Mar 4, 2026

CVE-2026-28434
MEDIUM

cpp-httplib's default exception handler leaks e.what() to clients via EXCEPTION_WHAT response header

Mar 4, 2026

CVE-2026-22776
HIGH

cpp-httplib vulnerable to a denial of service (DOS) using a zip bomb

Jan 12, 2026

CVE-2026-21428
HIGH

cpp-httplib has CRLF injection in http headers

Jan 1, 2026

CVE-2025-66577
MEDIUM

cpp-httplib Untrusted HTTP Header Handling: X-Forwarded-For/X-Real-IP Trust

Dec 5, 2025

CVE-2025-66570
CRITICAL

cpp-httplib Untrusted HTTP Header Handling: Internal Header Shadowing (REMOTE*/LOCAL*)

Dec 5, 2025

CVE-2025-53629
HIGH

cpp-httplib Unbounded Memory Allocation in Chunked/No-Length Requests Vulnerability

Jul 10, 2025

CVE-2025-53628
MEDIUM

cpp-httplib does not limit the length of a line

Jul 10, 2025

CVE-2025-52887
HIGH

cpp-httplib has unlimited number of http header fields, which causes memory leak

Jun 26, 2025

CVE-2025-46728
HIGH

cpp-httplib has Unbounded Memory Allocation in Chunked/No-Length Requests

May 6, 2025

CVE-2025-0825
MEDIUM

CRLF injection in Cpp-httplib

Feb 4, 2025

CVE-2023-26130
HIGH

cpp-httplib: CRLF Injection

May 30, 2023

CVE-2020-11709
HIGH

cpp-httplib through 0.5.8 does not filter \r\n in parameters passed into the set_redirect and set_header functions, whi…

Apr 12, 2020

Showing 1 to 24 of 24 CVEs