Description
Versions of the package yhirose/cpp-httplib before 0.12.4 are vulnerable to CRLF Injection when untrusted user input is used to set the content-type header in the HTTP .Patch, .Post, .Put and .Delete requests. This can lead to logical errors and other misbehaviors.

**Note:** This issue is present due to an incomplete fix for [CVE-2020-11709](https://security.snyk.io/vuln/SNYK-UNMANAGED-YHIROSECPPHTTPLIB-2366507).
Published: 2023-05-30
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-29977 Versions of the package yhirose/cpp-httplib before 0.12.4 are vulnerable to CRLF Injection when untrusted user input is used to set the content-type header in the HTTP .Patch, .Post, .Put and .Delete requests. This can lead to logical errors and other misbehaviors. **Note:** This issue is present due to an incomplete fix for [CVE-2020-11709](https://security.snyk.io/vuln/SNYK-UNMANAGED-YHIROSECPPHTTPLIB-2366507).
History

Wed, 28 May 2025 16:45:00 +0000

Type Values Removed Values Added
References

Thu, 22 May 2025 02:30:00 +0000


Mon, 28 Oct 2024 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Yhirose
Yhirose cpp-httplib
Weaknesses CWE-77
CPEs cpe:2.3:a:yhirose:cpp-httplib:*:*:*:*:*:*:*:*
Vendors & Products Yhirose
Yhirose cpp-httplib
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Cpp-httplib Project Cpp-httplib
Yhirose Cpp-httplib
cve-icon MITRE

Status: PUBLISHED

Assigner: snyk

Published:

Updated: 2025-02-13T16:44:51.068Z

Reserved: 2023-02-20T10:28:48.924Z

Link: CVE-2023-26130

cve-icon Vulnrichment

Updated: 2024-08-02T11:39:06.601Z

cve-icon NVD

Status : Modified

Published: 2023-05-30T05:15:10.640

Modified: 2024-11-21T07:50:50.233

Link: CVE-2023-26130

cve-icon Redhat

Severity : Low

Publid Date: 2023-05-30T00:00:00Z

Links: CVE-2023-26130 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses