Описание
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.44.0, when cpp-httplib's server parses an incoming request, it applies percent-decoding to every header value except Location and Referer. The validity check (is_field_value) is run before decoding, so encoded %0D%0A passes the check and is then expanded to a literal \r\n byte pair inside the stored header value. This vulnerability is fixed in 0.44.0.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | needs-triage | |
| esm-apps/jammy | released | 0.10.3+ds-1ubuntu0.1~esm2 |
| esm-apps/noble | released | 0.14.3+ds-1.1ubuntu0.1~esm2 |
| esm-apps/resolute | released | 0.26.0+ds-2ubuntu3+esm1 |
| jammy | needed | |
| noble | needed | |
| questing | released | 0.18.7-1ubuntu0.25.10.2 |
| resolute | needed | |
| upstream | needs-triage |
Показывать по
EPSS
9.9 Critical
CVSS3
Связанные уязвимости
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.44.0, when cpp-httplib's server parses an incoming request, it applies percent-decoding to every header value except Location and Referer. The validity check (is_field_value) is run before decoding, so encoded %0D%0A passes the check and is then expanded to a literal \r\n byte pair inside the stored header value. This vulnerability is fixed in 0.44.0.
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTT ...
Уязвимость функции parse_header() библиотеки cpp-httplib, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
EPSS
9.9 Critical
CVSS3