PT-2026-25380 · Unknown · Cpp-Httplib

0X3Xploit

·

Published

2026-01-01

·

Updated

2026-03-26

·

CVE-2026-32627

CVSS v3.1

8.7

High

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions cpp-httplib versions prior to 0.37.2
Description cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. When a cpp-httplib client is configured with a proxy and set follow location(true), HTTPS redirects can silently disable TLS certificate and hostname verification on the new connection. The client will accept any certificate presented by the redirect target—expired, self-signed, or forged—without raising an error or notifying the application. A network attacker positioned to return a redirect response can intercept the subsequent HTTPS connection, potentially including credentials or session tokens.
Recommendations Update cpp-httplib to version 0.37.2 or later.

Exploit

Fix

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

BDU:2026-04696
CVE-2026-32627
GHSA-C3H8-FQQ4-XM4G
OESA-2026-1637
OESA-2026-1638
OESA-2026-1639
OESA-2026-1640
OPENSUSE-SU-2026:10435-1

Affected Products

Cpp-Httplib