Security: yhirose/cpp-httplib
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
Use-after-free of TLS session in WebSocketClient::shutdown_and_close()GHSA-w7p7-f35j-mw7q published
Aug 21, 2026 by yhiroseModerate -
CRLF injection via unvalidated HTTP trailer headers in chunked response writingGHSA-2r2h-jc8w-w66c published
Aug 21, 2026 by yhiroseModerate -
TLS certificate chain verification bypassed for IP-literal hosts on Mbed TLS and wolfSSL backendsGHSA-8ffh-4p95-g3p2 published
Jun 16, 2026 by yhiroseHigh -
cpp-httplib: Malicious `X-Forwarded-For` Under Trusted-Proxy Configuration Triggers Empty `vector::front()`, Leading to Undefined Behavior and Server CrashGHSA-hg3g-vrg8-578g published
May 16, 2026 by yhiroseHigh -
HTTP header value percent-decoding in server-side `parse_header` enables CRLF injectionGHSA-xjxg-64p4-vj4m published
May 12, 2026 by yhiroseHigh -
DoS: Negative chunk-size in chunked Transfer-EncodingGHSA-h6wq-j5mv-f3q8 published
May 12, 2026 by yhiroseModerate -
HTTP Request Smuggling via Unconsumed GET Request BodyGHSA-jv63-rm9j-6jwc published
Mar 31, 2026 by yhiroseModerate -
cpp-httplib Client Leaks Authentication Credentials to Untrusted Hosts on Cross-Origin HTTP RedirectGHSA-6hrp-7fq9-3qv2 published
Mar 25, 2026 by yhiroseHigh -
Silent TLS Certificate Verification Bypass on HTTPS Redirect via ProxyGHSA-c3h8-fqq4-xm4g published
Mar 13, 2026 by yhiroseHigh -
Remote Process Crash via Malformed Content-Length Response HeaderGHSA-39q5-hh6x-jpxx published
Mar 10, 2026 by yhiroseHigh
Learn more about advisories related to yhirose/cpp-httplib in the GitHub Advisory Database