cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.20.1, cpp-httplib does not have a limit for a unique line, permitting an attacker to explore this to allocate memory arbitrarily. This vulnerability is fixed in 0.20.1. NOTE: This vulnerability is related to CVE-2025-53629.
{
"cna_assigner": "GitHub_M",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/53xxx/CVE-2025-53628.json",
"cwe_ids": [
"CWE-770",
"CWE-835"
]
}{
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "0.20.1"
}
],
"cpe": "cpe:2.3:a:yhirose:cpp-httplib:*:*:*:*:*:*:*:*",
"source": [
"CPE_RANGE",
"REFERENCES"
]
}[
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"length": 568.0,
"function_hash": "273893763024305777493719782969948749593"
},
"id": "CVE-2025-53628-18f6418d",
"signature_type": "Function",
"source": "https://github.com/yhirose/cpp-httplib/commit/7b752106ac42bd5b907793950d9125a0972c8e8e",
"target": {
"function": "stream_line_reader::getline",
"file": "httplib.h"
}
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"257985735793026435818868796645710254975",
"47152089635226046254886122597760746000",
"277935455136829786777737757595575415649",
"240428477853514944703987908155197738368",
"98734447240544736125538254896320203198",
"12401696439684324966363430957733437059",
"232918337349665503594913121985807921549",
"297344248686960807045559079316116779264",
"235855093667763522674929287323664717147",
"52669484370524566126415748220010415188"
]
},
"id": "CVE-2025-53628-1b351755",
"signature_type": "Line",
"source": "https://github.com/yhirose/cpp-httplib/commit/7b752106ac42bd5b907793950d9125a0972c8e8e",
"target": {
"file": "test/test.cc"
}
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"length": 19168.0,
"function_hash": "88011015293096735173591467930571185687"
},
"id": "CVE-2025-53628-d289d55f",
"signature_type": "Function",
"source": "https://github.com/yhirose/cpp-httplib/commit/7b752106ac42bd5b907793950d9125a0972c8e8e",
"target": {
"function": "SetUp",
"file": "test/test.cc"
}
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"32898783120307941874368505242798629186",
"162037324753814312112070594927690416950",
"287480307527108457454058770006969193908",
"301745308707818391118521842106411970281",
"263861363138065655965234048318932182331",
"218911545314115535196603612996816985361",
"260379456301400884034826106084209849017"
]
},
"id": "CVE-2025-53628-f50b3fbc",
"signature_type": "Line",
"source": "https://github.com/yhirose/cpp-httplib/commit/7b752106ac42bd5b907793950d9125a0972c8e8e",
"target": {
"file": "httplib.h"
}
}
]
"2026-07-22T04:02:18Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-53628.json"