We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-53628

cpp-httplib does not limit the length of a line



Description

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.20.1, cpp-httplib does not have a limit for a unique line, permitting an attacker to explore this to allocate memory arbitrarily. This vulnerability is fixed in 0.20.1. NOTE: This vulnerability is related to CVE-2025-53629.

Reserved 2025-07-07 | Published 2025-07-10 | Updated 2025-07-10 | Assigner GitHub_M


MEDIUM: 6.3CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Problem types

CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop')

CWE-770: Allocation of Resources Without Limits or Throttling

Product status

< 0.20.1
affected

References

github.com/...ttplib/security/advisories/GHSA-j6p8-779x-p5pw

github.com/...ttplib/security/advisories/GHSA-qjmq-h3cc-qv6w

github.com/...ommit/7b752106ac42bd5b907793950d9125a0972c8e8e

cve.org (CVE-2025-53628)

nvd.nist.gov (CVE-2025-53628)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-53628

Support options

Helpdesk Chat, Email, Knowledgebase