cpp-httplib是yhirose个人开发者的一款使用C++语言编写的HTTP/HTTPS服务器和客户端库。 cpp-httplib 0.43.4之前版本存在安全漏洞,该漏洞源于分块传输编码中负分块大小导致无界内存分配和进程崩溃,ChunkedDecoder::read_payload函数解析分块大小时使用strtoul接受前导负号,导致接近最大值存储并控制读取循环消耗网络字节。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| yhirose | cpp-httplib | < 0.43.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| yhirose | cpp-httplib | < 0.43.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-45372 | 9.9 CRITICAL | cpp-httplib: HTTP header value percent-decoding in server-side `parse_header` enables CRLF |
| CVE-2026-46527 | cpp-httplib: Malicious `X-Forwarded-For` Under Trusted-Proxy Configuration Triggers Empty |
No comments yet