CVE-2026-45372

EUVD-2026-33427
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.44.0, when cpp-httplib's server parses an incoming request, it applies percent-decoding to every header value except Location and Referer. The validity check (is_field_value) is run before decoding, so encoded %0D%0A passes the check and is then expanded to a literal \r\n byte pair inside the stored header value. This vulnerability is fixed in 0.44.0.
CRLF Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.9 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 21.45%
Affected Products (NVD)
VendorProductVersion
yhirosecpp-httplib
𝑥
< 0.44.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
cpp-httplib
bookworm
vulnerable
forky
vulnerable
sid
vulnerable
trixie
no-dsa
trixie (security)
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
cpp-httplib
jammy
Fixed 0.10.3+ds-1ubuntu0.1~esm2
released
noble
Fixed 0.14.3+ds-1.1ubuntu0.1~esm2
released
questing
Fixed 0.18.7-1ubuntu0.25.10.2
released
resolute
Fixed 0.26.0+ds-2ubuntu3+esm1
released