Yhirose

Cpp-httplib

22 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.4%
  • Veröffentlicht 04.02.2025 15:15:19
  • Zuletzt bearbeitet 04.08.2025 15:06:24

cpp-httplib version v0.17.3 through v0.18.3 fails to filter CRLF characters ("\r\n") when those are prefixed with a null byte. This enables attackers to exploit CRLF injection that could further lead to HTTP Response Splitting, XSS, and more.

Exploit
  • EPSS 1.64%
  • Veröffentlicht 12.04.2020 14:15:10
  • Zuletzt bearbeitet 05.08.2025 20:28:36

cpp-httplib through 0.5.8 does not filter \r\n in parameters passed into the set_redirect and set_header functions, which creates possibilities for CRLF injection and HTTP response splitting in some specific contexts.