Cpp-Httplib
Yhirose · 24 CVEs
cpp-httplib: Use-after-free of TLS session in WebSocketClient::shutdown_and_close()
Aug 27, 2026
cpp-httplib: CRLF injection via unvalidated HTTP trailer headers in chunked response writing
Aug 27, 2026
cpp-httplib: TLS certificate chain verification bypassed for IP-literal hosts on Mbed TLS and wolfSSL backends
Jul 10, 2026
cpp-httplib: HTTP header value percent-decoding in server-side `parse_header` enables CRLF injection
May 29, 2026
cpp-httplib: Malicious `X-Forwarded-For` Under Trusted-Proxy Configuration Triggers Empty `vector::front()`, Leading to…
May 29, 2026
cpp-httplib DoS: Negative chunk-size in chunked Transfer-Encoding
May 29, 2026
cpp-httplib: HTTP Request Smuggling via Unconsumed GET Request Body
Mar 31, 2026
cpp-httplib Client Leaks Authentication Credentials to Untrusted Hosts on Cross-Origin HTTP Redirect
Mar 27, 2026
cpp-httplib has a Silent TLS Certificate Verification Bypass on HTTPS Redirect via Proxy
Mar 13, 2026
cpp-httplib Affected by Remote Process Crash via Malformed Content-Length Response Header
Mar 11, 2026
cpp-httplib: Stack Overflow Denial of Service (DoS) via std::regex in multipart filename parsing
Mar 7, 2026
Payload size limit bypass via gzip decompression in ContentReader (streaming) allows oversized request bodies in cpp-ht…
Mar 4, 2026
cpp-httplib's default exception handler leaks e.what() to clients via EXCEPTION_WHAT response header
Mar 4, 2026
cpp-httplib vulnerable to a denial of service (DOS) using a zip bomb
Jan 12, 2026
cpp-httplib has CRLF injection in http headers
Jan 1, 2026
cpp-httplib Untrusted HTTP Header Handling: X-Forwarded-For/X-Real-IP Trust
Dec 5, 2025
cpp-httplib Untrusted HTTP Header Handling: Internal Header Shadowing (REMOTE*/LOCAL*)
Dec 5, 2025
cpp-httplib Unbounded Memory Allocation in Chunked/No-Length Requests Vulnerability
Jul 10, 2025
cpp-httplib does not limit the length of a line
Jul 10, 2025
cpp-httplib has unlimited number of http header fields, which causes memory leak
Jun 26, 2025
cpp-httplib has Unbounded Memory Allocation in Chunked/No-Length Requests
May 6, 2025
CRLF injection in Cpp-httplib
Feb 4, 2025
cpp-httplib: CRLF Injection
May 30, 2023
cpp-httplib through 0.5.8 does not filter \r\n in parameters passed into the set_redirect and set_header functions, whi…
Apr 12, 2020
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-77358 | cpp-httplib: Use-after-free of TLS session in WebSocketClient::shutdown_and_close() | HIGH | 0.45% | Aug 27, 2026 |
| CVE-2026-77341 | cpp-httplib: CRLF injection via unvalidated HTTP trailer headers in chunked response writing | MEDIUM | 0.46% | Aug 27, 2026 |
| CVE-2026-54919 | cpp-httplib: TLS certificate chain verification bypassed for IP-literal hosts on Mbed TLS and wolfSSL backends | HIGH | 0.26% | Jul 10, 2026 |
| CVE-2026-45372 | cpp-httplib: HTTP header value percent-decoding in server-side `parse_header` enables CRLF injection | CRITICAL | 0.41% | May 29, 2026 |
| CVE-2026-46527 | cpp-httplib: Malicious `X-Forwarded-For` Under Trusted-Proxy Configuration Triggers Empty `vector::front()`, Leading to Undefined Behavior and Server Crash | HIGH | 0.49% | May 29, 2026 |
| CVE-2026-45352 | cpp-httplib DoS: Negative chunk-size in chunked Transfer-Encoding | HIGH | 0.49% | May 29, 2026 |
| CVE-2026-34441 | cpp-httplib: HTTP Request Smuggling via Unconsumed GET Request Body | MEDIUM | 0.28% | Mar 31, 2026 |
| CVE-2026-33745 | cpp-httplib Client Leaks Authentication Credentials to Untrusted Hosts on Cross-Origin HTTP Redirect | HIGH | 0.35% | Mar 27, 2026 |
| CVE-2026-32627 | cpp-httplib has a Silent TLS Certificate Verification Bypass on HTTPS Redirect via Proxy | HIGH | 0.25% | Mar 13, 2026 |
| CVE-2026-31870 | cpp-httplib Affected by Remote Process Crash via Malformed Content-Length Response Header | HIGH | 0.55% | Mar 11, 2026 |
| CVE-2026-29076 | cpp-httplib: Stack Overflow Denial of Service (DoS) via std::regex in multipart filename parsing | MEDIUM | 0.61% | Mar 7, 2026 |
| CVE-2026-28435 | Payload size limit bypass via gzip decompression in ContentReader (streaming) allows oversized request bodies in cpp-httplib | HIGH | 0.62% | Mar 4, 2026 |
| CVE-2026-28434 | cpp-httplib's default exception handler leaks e.what() to clients via EXCEPTION_WHAT response header | MEDIUM | 0.43% | Mar 4, 2026 |
| CVE-2026-22776 | cpp-httplib vulnerable to a denial of service (DOS) using a zip bomb | HIGH | 0.40% | Jan 12, 2026 |
| CVE-2026-21428 | cpp-httplib has CRLF injection in http headers | HIGH | 0.41% | Jan 1, 2026 |
| CVE-2025-66577 | cpp-httplib Untrusted HTTP Header Handling: X-Forwarded-For/X-Real-IP Trust | MEDIUM | 0.27% | Dec 5, 2025 |
| CVE-2025-66570 | cpp-httplib Untrusted HTTP Header Handling: Internal Header Shadowing (REMOTE*/LOCAL*) | CRITICAL | 0.33% | Dec 5, 2025 |
| CVE-2025-53629 | cpp-httplib Unbounded Memory Allocation in Chunked/No-Length Requests Vulnerability | HIGH | 0.55% | Jul 10, 2025 |
| CVE-2025-53628 | cpp-httplib does not limit the length of a line | MEDIUM | 0.49% | Jul 10, 2025 |
| CVE-2025-52887 | cpp-httplib has unlimited number of http header fields, which causes memory leak | HIGH | 0.49% | Jun 26, 2025 |
| CVE-2025-46728 | cpp-httplib has Unbounded Memory Allocation in Chunked/No-Length Requests | HIGH | 0.66% | May 6, 2025 |
| CVE-2025-0825 | CRLF injection in Cpp-httplib | MEDIUM | 0.41% | Feb 4, 2025 |
| CVE-2023-26130 | cpp-httplib: CRLF Injection | HIGH | 1.14% | May 30, 2023 |
| CVE-2020-11709 | cpp-httplib through 0.5.8 does not filter \r\n in parameters passed into the set_redirect and set_header functions, which creates possibilities for CRLF inject… | HIGH | 1.68% | Apr 12, 2020 |
Showing 1 to 24 of 24 CVEs