cpp-httplib是yhirose个人开发者的一款使用C++语言编写的HTTP/HTTPS服务器和客户端库。 cpp-httplib 0.44.0之前版本存在代码问题漏洞,该漏洞源于当服务器设置了非空可信代理列表时,攻击者可发送包含X-Forwarded-For标头的HTTP请求,其值解析为无效IP段,导致对空std::vector调用front(),可能造成进程异常终止。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| yhirose | cpp-httplib | < 0.44.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| yhirose | cpp-httplib | < 0.44.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-45372 | 9.9 CRITICAL | cpp-httplib: HTTP header value percent-decoding in server-side `parse_header` enables CRLF |
| CVE-2026-45352 | 5.3 MEDIUM | cpp-httplib DoS: Negative chunk-size in chunked Transfer-Encoding |
No comments yet