PT-2026-25380 · Unknown · Cpp-Httplib

0X3Xploit

·

Publicado

2026-01-01

·

Atualizado

2026-03-26

·

CVE-2026-32627

CVSS v3.1

8.7

Alta

VetorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions cpp-httplib versions prior to 0.37.2
Description cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. When a cpp-httplib client is configured with a proxy and set follow location(true), HTTPS redirects can silently disable TLS certificate and hostname verification on the new connection. The client will accept any certificate presented by the redirect target—expired, self-signed, or forged—without raising an error or notifying the application. A network attacker positioned to return a redirect response can intercept the subsequent HTTPS connection, potentially including credentials or session tokens.
Recommendations Update cpp-httplib to version 0.37.2 or later.

Exploit

Correção

Improper Certificate Validation

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-04696
CVE-2026-32627
GHSA-C3H8-FQQ4-XM4G
OESA-2026-1637
OESA-2026-1638
OESA-2026-1639
OESA-2026-1640
OPENSUSE-SU-2026:10435-1

Produtos afetados

Cpp-Httplib