CVE-2025-0825

EUVD-2025-1886
cpp-httplib version v0.17.3 through v0.18.3 fails to filter CRLF characters ("\r\n") when those are prefixed with a null byte. This enables attackers to exploit CRLF injection that could further lead to HTTP Response Splitting, XSS, and more.
HTTP Request/Response Splitting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 33.5%
Affected Products (NVD)
VendorProductVersion
yhirosecpp-httplib
0.17.3 ≤
𝑥
< 0.18.4
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
cpp-httplib
bookworm
no-dsa
forky
0.41.0+ds-3
fixed
sid
0.41.0+ds-3
fixed
trixie
0.18.7-1+deb13u1
fixed
trixie (security)
0.18.7-1+deb13u1
fixed