A C++11 single-file header-only cross platform HTTP/HTTPS library. It's extremely easy to setup. Just include httplib.h file in your code!
Security Fix(es):
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to version 0.30.0, the write_headers function does not check for CR & LF characters in user supplied headers, allowing untrusted header value to escape header lines.
This vulnerability allows attackers to add extra headers, modify request body unexpectedly & trigger an SSRF attack. When combined with a server that supports http1.1 pipelining (springboot, python twisted etc), this can be used for server side request forgery (SSRF). Version 0.30.0 fixes this issue.(CVE-2026-21428)
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to version 0.30.1, a Denial of Service (DoS) vulnerability exists due to the unsafe handling of compressed HTTP request bodies (Content-Encoding: gzip, br, etc.). The library validates the payloadmaxlength against the compressed data size received from the network, but does not limit the size of the decompressed data stored in memory. An attacker can exploit this by sending a compressed payload with a very high compression ratio (e.g., a zip bomb), which upon decompression consumes excessive memory, leading to service unavailability.(CVE-2026-22776)
{
"severity": "High"
}{
"x86_64": [
"cpp-httplib-0.30.1-1.oe2403sp1.x86_64.rpm",
"cpp-httplib-debuginfo-0.30.1-1.oe2403sp1.x86_64.rpm",
"cpp-httplib-debugsource-0.30.1-1.oe2403sp1.x86_64.rpm",
"cpp-httplib-devel-0.30.1-1.oe2403sp1.x86_64.rpm"
],
"aarch64": [
"cpp-httplib-0.30.1-1.oe2403sp1.aarch64.rpm",
"cpp-httplib-debuginfo-0.30.1-1.oe2403sp1.aarch64.rpm",
"cpp-httplib-debugsource-0.30.1-1.oe2403sp1.aarch64.rpm",
"cpp-httplib-devel-0.30.1-1.oe2403sp1.aarch64.rpm"
],
"src": [
"cpp-httplib-0.30.1-1.oe2403sp1.src.rpm"
]
}