cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. In affected Mbed TLS backend versions from 0.31.0 through 0.46.1 and wolfSSL backend versions from 0.33.0 through 0.46.1, when cpp-httplib is built with CPPHTTPLIBMBEDTLSSUPPORT or CPPHTTPLIBWOLFSSLSUPPORT and a client connects to an IP-literal host with server certificate verification enabled, SSLClient and Client in HTTPS mode skip certificate chain validation and WebSocketClient on the Mbed TLS backend skips verification altogether, allowing a man-in-the-middle attacker positioned to intercept traffic to present a crafted certificate and read or modify the traffic. This issue is fixed in version 0.47.0.
{
"cwe_ids": [
"CWE-295"
],
"cna_assigner": "GitHub_M",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54919.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54919.json"
[
{
"source": "https://github.com/yhirose/cpp-httplib/commit/fa981cedae004ea9d946f1392b9dec22fac6fee6",
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"function_hash": "244798551285005665974849621235618061775",
"length": 723.0
},
"id": "CVE-2026-54919-0acb3b4c",
"target": {
"function": "create_session",
"file": "httplib.h"
},
"deprecated": false
},
{
"source": "https://github.com/yhirose/cpp-httplib/commit/fa981cedae004ea9d946f1392b9dec22fac6fee6",
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"function_hash": "278031654748316764174191698711485268180",
"length": 3259.0
},
"id": "CVE-2026-54919-7490be1b",
"target": {
"function": "SSLClient::initialize_ssl",
"file": "httplib.h"
},
"deprecated": false
},
{
"source": "https://github.com/yhirose/cpp-httplib/commit/fa981cedae004ea9d946f1392b9dec22fac6fee6",
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"function_hash": "307924959219438934718154579632510155064",
"length": 707.0
},
"id": "CVE-2026-54919-a055b838",
"target": {
"function": "setup_client_tls_session",
"file": "httplib.h"
},
"deprecated": false
},
{
"source": "https://github.com/yhirose/cpp-httplib/commit/fa981cedae004ea9d946f1392b9dec22fac6fee6",
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"line_hashes": [
"144921194235625452739821385354802835341",
"136669814074245045257425544155057133343",
"27192379669465510473157324134579042988",
"163399326708726824973930995457521119291",
"340109743481800934042365662765845019210",
"101965619034357326525895208379258731858",
"64381931785564330655444740385590579288",
"165723333409653731016397456908043763677",
"81498240525283296808452869204899841338",
"155183202003457392892155348293958155837",
"100066848822697791703681449479441291095"
],
"threshold": 0.9
},
"id": "CVE-2026-54919-b02dfc36",
"target": {
"file": "test/test.cc"
},
"deprecated": false
},
{
"source": "https://github.com/yhirose/cpp-httplib/commit/fa981cedae004ea9d946f1392b9dec22fac6fee6",
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"line_hashes": [
"212905938389791219969346567129228770860",
"202799028290577366164548141554788821169",
"118667971893695426822105552939577440663",
"60032273545905194150142696140994327529",
"101269862736788965282517352451002057789",
"129259446797443897337553839889754385128",
"62158931682984067047985401833866955204",
"307571031515548831018520065928885648702",
"90769778261657241502355293095136283541",
"254476919160950497784454623115050854315",
"124608378572964376674227634549596250054",
"19367668774447732001222073571306021139",
"68394706757768473660005774846428533823",
"140201705825498087054549233674519768056",
"98768426612556983068685011922940091514",
"25149630267970681269428793359934386521",
"269997167195884862064214766510865293994",
"272563558294974482851697352897125068052",
"3406660882268972728232359478839307605",
"319106081312209461952365416443855361048",
"200463488978713143216360649652952135797",
"214398334343658320078656907866823746822",
"159294198676799533912096471507418116964",
"50484886272397233794535172006099325643",
"266058586670752280522335767189654587033",
"46941585969860222459798424703601881811",
"186474517470884106482245279932690725124",
"31796160102422402338483368576859475711",
"52873434350248561492832753336681186328"
],
"threshold": 0.9
},
"id": "CVE-2026-54919-fb617a46",
"target": {
"file": "httplib.h"
},
"deprecated": false
}
]
"2026-07-22T03:57:25Z"