Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
CRLF injection in Cpp-httplib
Vulnerability Description
cpp-httplib version v0.17.3 through v0.18.3 fails to filter CRLF characters ("\r\n") when those are prefixed with a null byte. This enables attackers to exploit CRLF injection that could further lead to HTTP Response Splitting, XSS, and more.
CVSS Information
N/A
Vulnerability Type
HTTP头部中CRLF序列转义处理不恰当(HTTP响应分割)
Vulnerability Title
cpp-httplib 安全漏洞
Vulnerability Description
cpp-httplib是yhirose个人开发者的一款使用C++语言编写的HTTP/HTTPS服务器和客户端库。 cpp-httplib v0.17.3版本至v0.18.3版本存在安全漏洞,该漏洞源于无法过滤带有空字节前缀的CRLF字符,攻击者能够利用CRLF注入进一步导致HTTP响应拆分。
CVSS Information
N/A
Vulnerability Type
N/A