Yhirose

Cpp-httplib

22 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.29%
  • Veröffentlicht 27.08.2026 22:37:14
  • Zuletzt bearbeitet 09.09.2026 21:09:13

cpp-httplib is a C++ header-only HTTP/HTTPS library. In versions 0.33.0 through 0.50.0, the TLS-enabled WebSocket client frees the TLS session before closing the WebSocket that still uses it, producing a use-after-free. In WebSocketClient::shutdown_a...

  • EPSS 0.27%
  • Veröffentlicht 27.08.2026 22:16:45
  • Zuletzt bearbeitet 09.09.2026 21:09:13

cpp-httplib is a C++ header-only HTTP/HTTPS library. In version 0.49.0, the chunked-response trailer output path writes trailer header names and values directly to the socket without validating them, allowing CRLF sequences in a trailer field to inje...

  • EPSS 0.16%
  • Veröffentlicht 10.07.2026 16:06:12
  • Zuletzt bearbeitet 14.07.2026 05:16:18

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. In affected Mbed TLS backend versions from 0.31.0 through 0.46.1 and wolfSSL backend versions from 0.33.0 through 0.46.1, when cpp-httplib is built with CPPHTTPLIB_MBED...

Exploit
  • EPSS 0.3%
  • Veröffentlicht 29.05.2026 19:21:12
  • Zuletzt bearbeitet 22.07.2026 06:10:00

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.44.0, when cpp-httplib's server parses an incoming request, it applies percent-decoding to every header value except Location and Referer. The validity check...

Exploit
  • EPSS 0.33%
  • Veröffentlicht 29.05.2026 19:18:26
  • Zuletzt bearbeitet 22.07.2026 06:10:00

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.44.0, When the server has called Server::set_trusted_proxies() with a non-empty trusted-proxy list, an attacker can send an HTTP request that includes an X-F...

Exploit
  • EPSS 0.33%
  • Veröffentlicht 29.05.2026 19:14:08
  • Zuletzt bearbeitet 22.07.2026 06:10:00

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.43.4, negative chunk-size in chunked Transfer-Encoding causes unbounded memory allocation and process crash. The ChunkedDecoder::read_payload function in cpp...

Exploit
  • EPSS 0.2%
  • Veröffentlicht 31.03.2026 21:21:33
  • Zuletzt bearbeitet 24.07.2026 21:10:00

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to version 0.40.0, cpp-httplib is vulnerable to HTTP Request Smuggling. The server's static file handler serves GET responses without consuming the request body. ...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 27.03.2026 01:16:21
  • Zuletzt bearbeitet 01.04.2026 14:44:55

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.39.0, the cpp-httplib HTTP client forwards stored Basic Auth, Bearer Token, and Digest Auth credentials to arbitrary hosts when following cross-origin HTTP r...

Exploit
  • EPSS 0.18%
  • Veröffentlicht 13.03.2026 20:48:14
  • Zuletzt bearbeitet 17.03.2026 19:08:44

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.37.2, when a cpp-httplib client is configured with a proxy and set_follow_location(true), any HTTPS redirect it follows will have TLS certificate and hostnam...

Exploit
  • EPSS 0.45%
  • Veröffentlicht 11.03.2026 17:57:49
  • Zuletzt bearbeitet 18.03.2026 15:36:20

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.37.1, when a cpp-httplib client uses the streaming API (httplib::stream::Get, httplib::stream::Post, etc.), the library calls std::stoull() directly on the C...