CVE-2026-32627 affects cpp-httplib versions prior to 0.37.2, where a client configured with a proxy and set_follow_location(true) silently disables TLS certificate and hostname verification when following HTTPS redirects. Rated 8.1 HIGH, this vulnerability allows a network attacker to fully intercept subsequent HTTPS connections, including sensitive data, by presenting any certificate without error. The attack complexity is high, requiring the attacker to be in a position to return a redirect response. There is currently no known active exploitation or public exploit code, though the vulnerability is on a "Hot List" and has garnered some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.37.2CPE matchmatch criteria | cpe:2.3:a:yhirose:cpp-httplib:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.