We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-53629

cpp-httplib Unbounded Memory Allocation in Chunked/No-Length Requests Vulnerability



Description

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.23.0, incoming requests using Transfer-Encoding: chunked in the header can allocate memory arbitrarily in the server, potentially leading to its exhaustion. This vulnerability is fixed in 0.23.0. NOTE: This vulnerability is related to CVE-2025-53628.

Reserved 2025-07-07 | Published 2025-07-10 | Updated 2025-07-10 | Assigner GitHub_M


HIGH: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Problem types

CWE-770: Allocation of Resources Without Limits or Throttling

Product status

< 0.23.0
affected

References

github.com/...ttplib/security/advisories/GHSA-qjmq-h3cc-qv6w

github.com/...ttplib/security/advisories/GHSA-j6p8-779x-p5pw

github.com/...ommit/17ba303889b8d4d719be3879a70639ab653efb99

cve.org (CVE-2025-53629)

nvd.nist.gov (CVE-2025-53629)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-53629

Support options

Helpdesk Chat, Email, Knowledgebase