Lack of data validation In cpp-httplib
Description
cpp-httplib version v0.17.3 through v0.18.3 fails to filter CRLF characters ("\r\n") when those are prefixed with a null byte. This enables attackers to exploit CRLF injection that could further lead to HTTP Response Splitting, XSS, and more.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 14 | 0.18.7-1 | ||
debian 12 | - | ||
debian 13 | 0.18.7-1 |
Aliases
1. 2. 3. 4. 5.