Vulnerabilities
Vulnerable Software
Yhirose:  >> Cpp-Httplib  >> 0.18.0  Security Vulnerabilities
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.23.0, incoming requests using Transfer-Encoding: chunked in the header can allocate memory arbitrarily in the server, potentially leading to its exhaustion. This vulnerability is fixed in 0.23.0. NOTE: This vulnerability is related to CVE-2025-53628.
CVSS Score
7.5
EPSS Score
0.001
Published
2025-07-10
cpp-httplib version v0.17.3 through v0.18.3 fails to filter CRLF characters ("\r\n") when those are prefixed with a null byte. This enables attackers to exploit CRLF injection that could further lead to HTTP Response Splitting, XSS, and more.
CVSS Score
5.3
EPSS Score
0.001
Published
2025-02-04


Contact Us

Shodan ® - All rights reserved