CVE-2023-26130

HIGH

yhirose/cpp-httplib < 0.12.4 - CRLF Injection

Title source: llm
STIX 2.1

Description

Versions of the package yhirose/cpp-httplib before 0.12.4 are vulnerable to CRLF Injection when untrusted user input is used to set the content-type header in the HTTP .Patch, .Post, .Put and .Delete requests. This can lead to logical errors and other misbehaviors. **Note:** This issue is present due to an incomplete fix for [CVE-2020-11709](https://security.snyk.io/vuln/SNYK-UNMANAGED-YHIROSECPPHTTPLIB-2366507).

Scores

CVSS v3 7.5
EPSS 0.0019
EPSS Percentile 40.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-93 CWE-74 CWE-77
Status published
Products (1)
cpp-httplib_project/cpp-httplib < 0.12.4
Published May 30, 2023
Tracked Since Feb 18, 2026