PT-2026-1013 · Unknown+1 · Cpp-Httplib+1

·

CVE-2026-21428

·

Published

2026-01-01

·

Updated

2026-03-26

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions cpp-httplib versions prior to 0.30.0
Description The write headers function in cpp-httplib does not properly validate user-supplied headers, specifically failing to check for carriage return (CR) and line feed (LF) characters. This allows attackers to inject additional headers, potentially modify the request body, and trigger a Server-Side Request Forgery (SSRF) attack. When used with servers supporting HTTP/1.1 pipelining, the risk of SSRF is increased. The vulnerable component is the write headers function.
Recommendations Update to version 0.30.0 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-00006
CVE-2026-21428
GHSA-WPC6-J37R-JCX7
OPENSUSE-SU-2026:10435-1
OPENSUSE-SU-2026:20733-1
SUSE-SU-2026:21599-1

Affected Products

Debian
Cpp-Httplib