exploit-intel.com
Critical CRLF Injection Vulnerability in cpp-httplib (CVE-2026-45372)
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A critical vulnerability, CVE-2026-45372, has been identified in cpp-httplib, a C++11 HTTP/HTTPS library. The flaw allows attackers to inject carriage return and newline byte pairs into HTTP header values due to improper percent-decoding handling. This issue affects all versions prior to 0.44.0 and has a CVSS score of 9.9, indicating high severity. Exploitation requires network access to a vulnerable server, potentially leading to serious attacks such as response splitting and request smuggling. No public proof-of-concept exploits are available yet, but users are strongly advised to upgrade to version 0.44.0 or newer to mitigate the risk. The vulnerability was first reported on May 29, 2026.
Key Points: • CVE-2026-45372 is a critical CRLF injection vulnerability in cpp-httplib. • The flaw affects all versions prior to 0.44.0 and has a CVSS score of 9.9. • Users are urged to upgrade to cpp-httplib version 0.44.0 or later to mitigate risks.