Aller au contenu

Fiche vulnérabilité

CVE-2026-21428 : faille élevée yhirose cpp-httplib (CVSS 7.5)

Description

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to version 0.30.0, the ``write_headers`` function does not check for CR & LF characters in user supplied headers, allowing untrusted header value to escape header lines. This vulnerability allows attackers to add extra headers, modify request body unexpectedly & trigger an SSRF attack. When combined with a server that supports http1.1 pipelining (springboot, python twisted etc), this can be used for server side request forgery (SSRF). Version 0.30.0 fixes this issue.

En bref

Sévérité
Élevée (CVSS 7.5)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitation active
Non signalée par la CISA
Publication
1 janv. 2026
Dernière mise à jour
17 juin 2026

Produits concernés

  • yhirose cpp-httplib

Références

Rechercher une autre vulnérabilité dans la base CVE