cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.23.0, incoming requests using Transfer-Encoding: chunked in the header can allocate memory arbitrarily in the server, potentially leading to its exhaustion. This vulnerability is fixed in 0.23.0. NOTE: This vulnerability is related to CVE-2025-53628.
{
"cwe_ids": [
"CWE-770"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/53xxx/CVE-2025-53629.json",
"cna_assigner": "GitHub_M"
}{
"cpe": "cpe:2.3:a:yhirose:cpp-httplib:*:*:*:*:*:*:*:*",
"source": [
"CPE_RANGE",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "0.23.0"
}
]
}"2026-07-15T20:54:36Z"
[
{
"signature_type": "Line",
"target": {
"file": "httplib.h"
},
"deprecated": false,
"source": "https://github.com/yhirose/cpp-httplib/commit/17ba303889b8d4d719be3879a70639ab653efb99",
"id": "CVE-2025-53629-51536f41",
"signature_version": "v1",
"digest": {
"line_hashes": [
"205226579118729805217032180192572666325",
"288326940859781463957734342028996878695",
"297363821923707760301441192804047150422",
"306354135440132806753468599416133555670",
"332961119277007769851213870930383911487",
"218006389939506568329658419390594466106",
"140021593573549170605239541653318080358",
"120576207178700527404694121735721518876",
"53237574012263135774486892352033226510",
"292634964069883026736939148290991205255",
"307015537166185343876694251539742520392",
"132516790775411026159359503908778088653",
"169837434549799774299341236548756316779",
"292335094172956404578648148576097864303",
"259254892090884070752440449394210209075",
"164380346724209714837267416781148998330",
"59423945478876370211613438286834497724",
"179017214993518399257847108043015089395",
"247055664394971458722388735134688385937",
"142383695468159561099580613468756248028",
"304167139755899475484609117919485067791",
"271218819453716100754564275103897560218",
"93695726838761958007818518629843454012",
"49850466351355713629992903153275447867",
"269529242931526513953273825685870424713",
"246341959574433841927344090040453605083",
"104200263907913986650594648025431208928",
"201599137572375611230894186625871262686",
"34454009186070578903854342300730811724",
"23222426063267238159999575072059450696",
"279196033155740987593201962810448484335",
"111661590877232261277549872926427177169",
"196912973415306529857786817635776453596"
],
"threshold": 0.9
}
},
{
"signature_type": "Function",
"target": {
"file": "httplib.h",
"function": "read_content_chunked"
},
"deprecated": false,
"source": "https://github.com/yhirose/cpp-httplib/commit/17ba303889b8d4d719be3879a70639ab653efb99",
"id": "CVE-2025-53629-d6331234",
"signature_version": "v1",
"digest": {
"function_hash": "300647741648752637084487631199956454766",
"length": 1475.0
}
},
{
"signature_type": "Line",
"target": {
"file": "test/test.cc"
},
"deprecated": false,
"source": "https://github.com/yhirose/cpp-httplib/commit/17ba303889b8d4d719be3879a70639ab653efb99",
"id": "CVE-2025-53629-ddf24767",
"signature_version": "v1",
"digest": {
"line_hashes": [
"71835222838686621250286688722251933616",
"276584867859912751115153440147786483036",
"291578792499164081159744552859857304325",
"116780648414751796823354903953399496260",
"289036440152358346294886277958434667601",
"332570344452481549640569201778889365754"
],
"threshold": 0.9
}
},
{
"signature_type": "Function",
"target": {
"file": "test/test.cc",
"function": "TEST_F"
},
"deprecated": false,
"source": "https://github.com/yhirose/cpp-httplib/commit/17ba303889b8d4d719be3879a70639ab653efb99",
"id": "CVE-2025-53629-f7fb1db0",
"signature_version": "v1",
"digest": {
"function_hash": "100031104252767916215606970190726631503",
"length": 390.0
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-53629.json"