We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2023-26130



Description

Versions of the package yhirose/cpp-httplib before 0.12.4 are vulnerable to CRLF Injection when untrusted user input is used to set the content-type header in the HTTP .Patch, .Post, .Put and .Delete requests. This can lead to logical errors and other misbehaviors. **Note:** This issue is present due to an incomplete fix for [CVE-2020-11709](https://security.snyk.io/vuln/SNYK-UNMANAGED-YHIROSECPPHTTPLIB-2366507).

Reserved 2023-02-20 | Published 2023-05-30 | Updated 2025-02-13 | Assigner snyk


HIGH: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Problem types

CRLF Injection

Credits

Alessio Della Libera

References

security.snyk.io/...SNYK-UNMANAGED-YHIROSECPPHTTPLIB-5591194

gist.github.com/dellalibera/094aece17a86069a7d27f93c8aba2280

github.com/yhirose/cpp-httplib/releases/tag/v0.12.4

github.com/...ommit/5b397d455d25a391ba346863830c1949627b4d08

lists.fedoraproject.org/...JY2E7EIRWQMKH6GY4OZOWWBZBY3Q7CGS/

lists.fedoraproject.org/...U6MO4FSKYNSAJVUXYP7LRY7ARUIGKBFL/

lists.fedoraproject.org/...2RY6PKBU73I45L6YWNYCUK2XBEXEFX7L/

lists.fedoraproject.org/...NYODHZECXYFC2BNODZPZXZAXOKGMCYAP/

cve.org (CVE-2023-26130)

nvd.nist.gov (CVE-2023-26130)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2023-26130

Support options

Helpdesk Chat, Email, Knowledgebase