Cpp Httplib Project maintains a lightweight, header-only HTTP client library for C++ that sees integration into embedded applications and tooling where minimal dependencies are preferred. The modest vulnerability surface reflects the narrowly scoped, parser-oriented nature of the library; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cpp Httplib Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-26130HIGH Versions of the package yhirose/cpp-httplib before 0.12.4 are vulnerable to CRLF Injection when untrusted user input is used to set the content-type header in the HTTP .Patch, .Pos | May 30, 2023 | 8.8 | 26 | NO | NO |
CVE-2025-46728HIGH cpp-httplib is a C++ header-only HTTP/HTTPS server and client library. Prior to version 0.20.1, the library fails to enforce configured size limits on incoming request bodies when | May 6, 2025 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cpp Httplib Project.
Media articles that mention a CVE ID that affects a product developed by Cpp Httplib Project — matched by CVE ID, not by vendor name.