Yhirose maintains a focused C++ HTTP library (cpp-httplib) that, despite narrow scope, sees adoption across embedded and integration use cases where HTTP parsing and request handling are critical. Vulnerabilities affecting this library skew toward serious outcomes and cluster around protocol-parsing and resource-handling weaknesses, including HTTP request smuggling, CRLF injection, unthrottled resource allocation, and improper handling of compressed data—all of which reflect the attack surface inherent to a network-facing parser. Defenders using this library should monitor upstream advisories closely and prioritize patches for internet-exposed services; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yhirose over time
Signals from CVEs in this vendor scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-45372CRITICAL cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.44.0, when cpp-httplib's server parses an incoming request, it applies percent-decoding | May 29, 2026 | 9.9 | 40 | NO | NO |
CVE-2025-66570CRITICAL cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.27.0, a vulnerability allows attacker-controlled HTTP headers to influence server-visib | Dec 5, 2025 | 9.8 | 33 | NO | NO |
CVE-2026-46527HIGH cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.44.0, When the server has called Server::set_trusted_proxies() with a non-empty trusted | May 29, 2026 | 7.5 | 32 | NO | NO |
CVE-2026-54919HIGH cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. In affected Mbed TLS backend versions from 0.31.0 through 0.46.1 and wolfSSL backend versions from | Jul 10, 2026 | 7.4 | 31 | NO | NO |
CVE-2026-45352HIGH cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.43.4, negative chunk-size in chunked Transfer-Encoding causes unbounded memory allocati | May 29, 2026 | 7.5 | 31 | NO | NO |
CVE-2026-32627HIGH cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.37.2, when a cpp-httplib client is configured with a proxy and set_follow_location(true | Mar 13, 2026 | 8.1 | 28 | NO | NO |
CVE-2026-28435HIGH cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.35.0, cpp-httplib (httplib.h) does not enforce Server::set_payload_max_length() on the | Mar 4, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-33745HIGH cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.39.0, the cpp-httplib HTTP client forwards stored Basic Auth, Bearer Token, and Digest | Mar 27, 2026 | 7.4 | 25 | NO | NO |
CVE-2026-31870HIGH cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.37.1, when a cpp-httplib client uses the streaming API (httplib::stream::Get, httplib:: | Mar 11, 2026 | 7.5 | 25 | NO | NO |
CVE-2026-22776HIGH cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to version 0.30.1, a Denial of Service (DoS) vulnerability exists in cpp-httplib due to the | Jan 12, 2026 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (20 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yhirose.
Media articles that mention a CVE ID that affects a product developed by Yhirose — matched by CVE ID, not by vendor name.