PT-2025-19817 · Unknown+2 · Cpp-Httplib+2

·

CVE-2025-46728

·

Published

2025-05-06

·

Updated

2025-12-05

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions cpp-httplib versions prior to 0.20.1
Description cpp-httplib is a C++ header-only HTTP/HTTPS server and client library. Versions prior to 0.20.1 do not enforce configured size limits on incoming request bodies when Transfer-Encoding: chunked is used or when no Content-Length header is provided. This allows a remote attacker to send a chunked request without the terminating zero-length chunk, leading to uncontrolled memory allocation. This can result in exhaustion of system memory and a server crash or unresponsiveness.
Recommendations Upgrade to cpp-httplib version 0.20.1 or later. As a temporary workaround, deploy a reverse proxy (e.g., Nginx, HAProxy) and configure it to enforce maximum request body size limits.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-10262
BDU:2026-00239
CVE-2025-46728
ECHO-F24E-40E5-BA8E
GHSA-PX83-72RX-V57C
OESA-2025-1610
OESA-2025-1611
OESA-2025-1612
OESA-2025-1613
OPENSUSE-SU-2025:15084-1

Affected Products

Alt Linux
Debian
Cpp-Httplib