Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-53629

Опубликовано: 10 июл. 2025
Источник: debian
EPSS Низкий

Описание

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.23.0, incoming requests using Transfer-Encoding: chunked in the header can allocate memory arbitrarily in the server, potentially leading to its exhaustion. This vulnerability is fixed in 0.23.0. NOTE: This vulnerability is related to CVE-2025-53628.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
cpp-httplibfixed0.25.0+ds-1experimentalpackage
cpp-httplibfixed0.25.0+ds-3package
cpp-httplibpostponedbookwormpackage

Примечания

  • https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-qjmq-h3cc-qv6w

  • https://github.com/yhirose/cpp-httplib/commit/082acacd4581d10e05fccbe9cb336aa7822c4ea2 (v0.23.0)

EPSS

Процентиль: 41%
0.00505
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 года назад

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.23.0, incoming requests using Transfer-Encoding: chunked in the header can allocate memory arbitrarily in the server, potentially leading to its exhaustion. This vulnerability is fixed in 0.23.0. NOTE: This vulnerability is related to CVE-2025-53628.

CVSS3: 7.5
nvd
около 1 года назад

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.23.0, incoming requests using Transfer-Encoding: chunked in the header can allocate memory arbitrarily in the server, potentially leading to its exhaustion. This vulnerability is fixed in 0.23.0. NOTE: This vulnerability is related to CVE-2025-53628.

CVSS3: 7.5
fstec
около 1 года назад

Уязвимость библиотеки cpp-httplib, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

suse-cvrf
6 месяцев назад

Security update for cpp-httplib

EPSS

Процентиль: 41%
0.00505
Низкий