Vulnerability Description
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.44.0, when cpp-httplib's server parses an incoming request, it applies percent-decoding to every header value except Location and Referer. The validity check (is_field_value) is run before decoding, so encoded %0D%0A passes the check and is then expanded to a literal \r\n byte pair inside the stored header value. This vulnerability is fixed in 0.44.0.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Yhirose | Cpp-Httplib | < 0.44.0 |
Related Weaknesses (CWE)
References
- https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-xjxg-64p4-vj4mExploitMitigationVendor Advisory
- https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-xjxg-64p4-vj4mExploitMitigationVendor Advisory
FAQ
What is CVE-2026-45372?
CVE-2026-45372 is a vulnerability with a CVSS score of 9.9 (CRITICAL). cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.44.0, when cpp-httplib's server parses an incoming request, it applies percent-decoding to every header val...
How severe is CVE-2026-45372?
CVE-2026-45372 has been rated CRITICAL with a CVSS base score of 9.9/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-45372?
Check the references section above for vendor advisories and patch information. Affected products include: Yhirose Cpp-Httplib.