PT-2026-82795 · Unknown · Cpp-Httplib
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
cpp-httplib versions prior to 0.50.0
Description
The chunked-response trailer output path writes trailer header names and values directly to the socket without validation. This lack of checks for carriage return (CR) and line feed (LF) sequences allows an attacker to inject CRLF sequences into a trailer field. This leads to HTTP response splitting, which enables the forgery of response headers or the injection of a second response when an application includes attacker-influenced data in a chunked response trailer.
Recommendations
Update to version 0.50.0.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cpp-Httplib