PT-2026-1013 · Unknown+1 · Cpp-Httplib+1
Hritik14
·
Published
2026-01-01
·
Updated
2026-03-26
·
CVE-2026-21428
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
cpp-httplib versions prior to 0.30.0
Description
The
write headers function in cpp-httplib does not properly validate user-supplied headers, specifically failing to check for carriage return (CR) and line feed (LF) characters. This allows attackers to inject additional headers, potentially modify the request body, and trigger a Server-Side Request Forgery (SSRF) attack. When used with servers supporting HTTP/1.1 pipelining, the risk of SSRF is increased. The vulnerable component is the write headers function.Recommendations
Update to version 0.30.0 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Cpp-Httplib