PT-2026-82795 · Unknown · Cpp-Httplib

·

CVE-2026-77341

·

Published

2026-08-27

·

Updated

2026-08-28

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions cpp-httplib versions prior to 0.50.0
Description The chunked-response trailer output path writes trailer header names and values directly to the socket without validation. This lack of checks for carriage return (CR) and line feed (LF) sequences allows an attacker to inject CRLF sequences into a trailer field. This leads to HTTP response splitting, which enables the forgery of response headers or the injection of a second response when an application includes attacker-influenced data in a chunked response trailer.
Recommendations Update to version 0.50.0.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77341
GHSA-2R2H-JC8W-W66C

Affected Products

Cpp-Httplib