Vendorsyhirosecpp-httpliball versions
Vulnerabilities

yhirose cpp-httplib

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

20CVEs
CVE-2025-66570
cpp-httplib Untrusted HTTP Header Handling: Internal Header Shadowing (REMOTE*/LOCAL*)
Published 2025-12-05 · Analyzed
10.0EPSS 0.003
CVE-2026-45372
cpp-httplib: HTTP header value percent-decoding in server-side `parse_header` enables CRLF injection
Published 2026-05-29 · Modified
9.9EPSS 0.003
CVE-2025-53628
cpp-httplib does not limit the length of a line
Published 2025-07-10 · Analyzed
8.8EPSS 0.005
CVE-2026-22776
cpp-httplib vulnerable to a denial of service (DOS) using a zip bomb
Published 2026-01-12 · Analyzed
8.7EPSS 0.004
CVE-2026-46527
cpp-httplib: Malicious `X-Forwarded-For` Under Trusted-Proxy Configuration Triggers Empty `vector::front()`, Leading to Undefined Behavior and Server Crash
Published 2026-05-29 · Analyzed
8.7EPSS 0.003
CVE-2026-32627
cpp-httplib has a Silent TLS Certificate Verification Bypass on HTTPS Redirect via Proxy
Published 2026-03-13 · Analyzed
8.7EPSS 0.002
CVE-2026-21428
cpp-httplib has CRLF injection in http headers
Published 2026-01-01 · Analyzed
7.7EPSS 0.004
CVE-2020-11709
cpp-httplib through 0.5.8 does not filter \r\n in parameters passed into the set_redirect and set_header functions, which creates possibilities for CRLF injection and HTTP response splitting in some specific contexts.
Published 2020-04-12 · Modified
7.5EPSS 0.017
CVE-2025-53629
cpp-httplib Unbounded Memory Allocation in Chunked/No-Length Requests Vulnerability
Published 2025-07-10 · Analyzed
7.5EPSS 0.005
CVE-2025-52887
cpp-httplib has unlimited number of http header fields, which causes memory leak
Published 2025-06-26 · Analyzed
7.5EPSS 0.005
CVE-2026-31870
cpp-httplib Affected by Remote Process Crash via Malformed Content-Length Response Header
Published 2026-03-11 · Analyzed
7.5EPSS 0.005
CVE-2026-28435
Payload size limit bypass via gzip decompression in ContentReader (streaming) allows oversized request bodies in cpp-httplib
Published 2026-03-04 · Analyzed
7.5EPSS 0.004
CVE-2026-45352
cpp-httplib DoS: Negative chunk-size in chunked Transfer-Encoding
Published 2026-05-29 · Modified
7.5EPSS 0.003
CVE-2026-54919
cpp-httplib: TLS certificate chain verification bypassed for IP-literal hosts on Mbed TLS and wolfSSL backends
Published 2026-07-10 · Analyzed
7.4EPSS 0.003
CVE-2026-33745
cpp-httplib Client Leaks Authentication Credentials to Untrusted Hosts on Cross-Origin HTTP Redirect
Published 2026-03-27 · Analyzed
7.4EPSS 0.003
CVE-2025-0825
CRLF injection in Cpp-httplib
Published 2025-02-04 · Analyzed
6.9EPSS 0.004
CVE-2026-34441
cpp-httplib: HTTP Request Smuggling via Unconsumed GET Request Body
Published 2026-03-31 · Analyzed
6.5EPSS 0.002
CVE-2026-29076
cpp-httplib: Stack Overflow Denial of Service (DoS) via std::regex in multipart filename parsing
Published 2026-03-07 · Analyzed
5.9EPSS 0.006
CVE-2026-28434
cpp-httplib's default exception handler leaks e.what() to clients via EXCEPTION_WHAT response header
Published 2026-03-04 · Analyzed
5.3EPSS 0.003
CVE-2025-66577
cpp-httplib Untrusted HTTP Header Handling: X-Forwarded-For/X-Real-IP Trust
Published 2025-12-05 · Analyzed
5.3EPSS 0.003