CVE-2026-54919

Source
https://cve.org/CVERecord?id=CVE-2026-54919
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54919.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-54919
Aliases
  • GHSA-8ffh-4p95-g3p2
Downstream
Published
2026-07-10T16:06:12.848Z
Modified
2026-07-22T03:57:25.686254Z
Severity
  • 7.4 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
cpp-httplib: TLS certificate chain verification bypassed for IP-literal hosts on Mbed TLS and wolfSSL backends
Details

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. In affected Mbed TLS backend versions from 0.31.0 through 0.46.1 and wolfSSL backend versions from 0.33.0 through 0.46.1, when cpp-httplib is built with CPPHTTPLIBMBEDTLSSUPPORT or CPPHTTPLIBWOLFSSLSUPPORT and a client connects to an IP-literal host with server certificate verification enabled, SSLClient and Client in HTTPS mode skip certificate chain validation and WebSocketClient on the Mbed TLS backend skips verification altogether, allowing a man-in-the-middle attacker positioned to intercept traffic to present a crafted certificate and read or modify the traffic. This issue is fixed in version 0.47.0.

Database specific
{
    "cwe_ids": [
        "CWE-295"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54919.json"
}
References

Affected packages

Git / github.com/yhirose/cpp-httplib

Affected ranges

Type
GIT
Repo
https://github.com/yhirose/cpp-httplib
Events
Database specific
{
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ],
    "cpe": "cpe:2.3:a:yhirose:cpp-httplib:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0.31.0"
        },
        {
            "fixed": "0.47.0"
        }
    ]
}

Affected versions

Other
latest
v0.*
v0.31.0
v0.32.0
v0.33.0
v0.33.1
v0.34.0
v0.35.0
v0.37.0
v0.37.1
v0.37.2
v0.38.0
v0.39.0
v0.40.0
v0.41.0
v0.42.0
v0.43.0
v0.43.1
v0.43.2
v0.43.3
v0.43.4
v0.44.0
v0.45.0
v0.45.1
v0.46.0
v0.46.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54919.json"
vanir_signatures
[
    {
        "source": "https://github.com/yhirose/cpp-httplib/commit/fa981cedae004ea9d946f1392b9dec22fac6fee6",
        "signature_type": "Function",
        "signature_version": "v1",
        "digest": {
            "function_hash": "244798551285005665974849621235618061775",
            "length": 723.0
        },
        "id": "CVE-2026-54919-0acb3b4c",
        "target": {
            "function": "create_session",
            "file": "httplib.h"
        },
        "deprecated": false
    },
    {
        "source": "https://github.com/yhirose/cpp-httplib/commit/fa981cedae004ea9d946f1392b9dec22fac6fee6",
        "signature_type": "Function",
        "signature_version": "v1",
        "digest": {
            "function_hash": "278031654748316764174191698711485268180",
            "length": 3259.0
        },
        "id": "CVE-2026-54919-7490be1b",
        "target": {
            "function": "SSLClient::initialize_ssl",
            "file": "httplib.h"
        },
        "deprecated": false
    },
    {
        "source": "https://github.com/yhirose/cpp-httplib/commit/fa981cedae004ea9d946f1392b9dec22fac6fee6",
        "signature_type": "Function",
        "signature_version": "v1",
        "digest": {
            "function_hash": "307924959219438934718154579632510155064",
            "length": 707.0
        },
        "id": "CVE-2026-54919-a055b838",
        "target": {
            "function": "setup_client_tls_session",
            "file": "httplib.h"
        },
        "deprecated": false
    },
    {
        "source": "https://github.com/yhirose/cpp-httplib/commit/fa981cedae004ea9d946f1392b9dec22fac6fee6",
        "signature_type": "Line",
        "signature_version": "v1",
        "digest": {
            "line_hashes": [
                "144921194235625452739821385354802835341",
                "136669814074245045257425544155057133343",
                "27192379669465510473157324134579042988",
                "163399326708726824973930995457521119291",
                "340109743481800934042365662765845019210",
                "101965619034357326525895208379258731858",
                "64381931785564330655444740385590579288",
                "165723333409653731016397456908043763677",
                "81498240525283296808452869204899841338",
                "155183202003457392892155348293958155837",
                "100066848822697791703681449479441291095"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-54919-b02dfc36",
        "target": {
            "file": "test/test.cc"
        },
        "deprecated": false
    },
    {
        "source": "https://github.com/yhirose/cpp-httplib/commit/fa981cedae004ea9d946f1392b9dec22fac6fee6",
        "signature_type": "Line",
        "signature_version": "v1",
        "digest": {
            "line_hashes": [
                "212905938389791219969346567129228770860",
                "202799028290577366164548141554788821169",
                "118667971893695426822105552939577440663",
                "60032273545905194150142696140994327529",
                "101269862736788965282517352451002057789",
                "129259446797443897337553839889754385128",
                "62158931682984067047985401833866955204",
                "307571031515548831018520065928885648702",
                "90769778261657241502355293095136283541",
                "254476919160950497784454623115050854315",
                "124608378572964376674227634549596250054",
                "19367668774447732001222073571306021139",
                "68394706757768473660005774846428533823",
                "140201705825498087054549233674519768056",
                "98768426612556983068685011922940091514",
                "25149630267970681269428793359934386521",
                "269997167195884862064214766510865293994",
                "272563558294974482851697352897125068052",
                "3406660882268972728232359478839307605",
                "319106081312209461952365416443855361048",
                "200463488978713143216360649652952135797",
                "214398334343658320078656907866823746822",
                "159294198676799533912096471507418116964",
                "50484886272397233794535172006099325643",
                "266058586670752280522335767189654587033",
                "46941585969860222459798424703601881811",
                "186474517470884106482245279932690725124",
                "31796160102422402338483368576859475711",
                "52873434350248561492832753336681186328"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-54919-fb617a46",
        "target": {
            "file": "httplib.h"
        },
        "deprecated": false
    }
]
vanir_signatures_modified
"2026-07-22T03:57:25Z"