CVE-2025-66570 is a critical vulnerability in cpp-httplib versions prior to 0.27.0, a C++11 HTTP/HTTPS library, allowing attackers to inject spoofed HTTP headers like REMOTE_ADDR and LOCAL_ADDR. This header shadowing can lead to IP spoofing, log poisoning, and authorization bypasses in applications using the library. With a CVSS score of 9.8 (CRITICAL), the vulnerability is easily exploitable over the network with low complexity and no user interaction, potentially impacting confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered community attention, with a single mention on Mastodon urging immediate upgrades.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.27.0CPE matchmatch criteria | cpe:2.3:a:yhirose:cpp-httplib:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.