Skip to content

vendor : update cpp-httplib to 0.50.0 and 0.50.1 - #25576

Merged
ngxson merged 1 commit into
ggml-org:masterfrom
cabelo:cpp-httplib-0.50.1
Jul 12, 2026
Merged

ngxson merged 1 commit into
ggml-org:masterfrom
cabelo:cpp-httplib-0.50.1

Conversation

@cabelo

@cabelo cabelo commented Jul 12, 2026 •

Copy link
Copy Markdown
Contributor

Overview

Additional information

Requirements

Overview

Additional information

Requirements

What's Changed

v0.50.1

Security fixes

  • Fix use-after-free of TLS session in WebSocketClient::shutdown_and_close() (GHSA-w7p7-f35j-mw7q). shutdown_and_close() freed the TLS session before ws_->close() sent the WebSocket close frame. The WebSocket's SSLSocketStream keeps a raw pointer to that session, so sending the close frame read/wrote a freed SSL object. This affects any wss:// client that is destroyed (or reconnected via connect()) while the connection is still open, without an explicit close() first. The close frame is now sent while the session is still alive, and the session is freed afterward. Regression tests covering both the destroy-while-open and reconnect-while-open paths were added

v0.50.0

Security fixes

  • Fix CRLF injection in chunked response trailers. Trailer field names and values written via DataSink::done_with_trailer() were never validated, unlike every other header output path (set_header, WebSocket handshake, client request headers). An application reflecting untrusted input into a trailer could inject CR/LF sequences and achieve HTTP response splitting. Trailer fields with invalid names or values are now silently skipped, matching set_header()'s existing behavior

Breaking changes

  • Add Get(path, params, progress) overload to ClientImpl/Client. This makes calls that pass a headers argument as a braced initializer list — e.g. cli.Get(path, {{"Accept", "..."}}) — ambiguous between the existing Get(path, headers) overload and the new Get(path, params) overload, since {{...}} can construct either Headers or Params. Existing code relying on that implicit conversion will fail to compile with an "ambiguous call" error; disambiguate by wrapping the argument explicitly, e.g. cli.Get(path, Headers{{"Accept", "..."}}). All in-tree call sites (test.cc, test_proxy.cc, README) were updated to do this

Bug fixes

  • Fix use-after-free in SSLClient destructor with mbedTLS . SSLClient::~SSLClient() freed the TLS context before shutting down the SSL session. mbedTLS sessions hold a raw pointer into the context's mbedtls_ssl_config, so a live keep-alive session's close_notify could read freed memory. The session is now shut down before the context is freed
  • Fix Response::content_length_ not reflecting body size in Logger . Server::apply_ranges computed the correct Content-Length header for body-based responses but never updated content_length_, so the Logger callback always saw 0. It now reflects the final body size (post-range/post-compression)

Docs

  • Fix README WebSocket example to match actual API. The quick preview referenced a nonexistent httplib::ws::Message type with .is_text()/.data; the actual API uses a plain std::string with ws.read(msg), as already shown in README-websocket.md
  • Fix broken relative links in cookbook docs. Cookbook body links referenced sibling pages with a bare slug (e.g. c14-keep-alive), which 404 under the pretty-URL layout since each page lives in its own directory. Links are now prefixed with ../ to match convention

@cabelo
cabelo marked this pull request as ready for review July 12, 2026 03:23
@cabelo
cabelo requested a review from ggerganov as a code owner July 12, 2026 03:23
@ngxson
ngxson merged commit 3455882 into ggml-org:master Jul 12, 2026
26 of 28 checks passed
@cabelo
cabelo deleted the cpp-httplib-0.50.1 branch July 31, 2026 04:07
satindergrewal pushed a commit to satindergrewal/llama.cpp that referenced this pull request Aug 12, 2026
zbrad pushed a commit to zbrad/llama.cpp that referenced this pull request Sep 10, 2026
pl752 pushed a commit to pl752/llama.cpp that referenced this pull request Sep 15, 2026
frostyautumnleaf pushed a commit to frostyautumnleaf/llama.cpp that referenced this pull request Oct 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants