Critical CRLF Injection Vulnerability in cpp-httplib (CVE-2026-45372)

Critical CRLF Injection Vulnerability in cpp-httplib (CVE-2026-45372)

First seen 30 May 2026, 17:25 UTC Feedlyexploit-intel.comwww.thehackerwire.cominfosec.exchangevuldb.com 94% similarity 72.6

Article Content

Browse articles
ThreatCluster

A critical vulnerability, CVE-2026-45372, has been identified in cpp-httplib, a C++11 HTTP/HTTPS library. The flaw allows attackers to inject carriage return and newline byte pairs into HTTP header values due to improper percent-decoding handling. This issue affects all versions prior to 0.44.0 and has a CVSS score of 9.9, indicating high severity. Exploitation requires network access to a vulnerable server, potentially leading to serious attacks such as response splitting and request smuggling. No public proof-of-concept exploits are available yet, but users are strongly advised to upgrade to version 0.44.0 or newer to mitigate the risk. The vulnerability was first reported on May 29, 2026.

Key Points: • CVE-2026-45372 is a critical CRLF injection vulnerability in cpp-httplib. • The flaw affects all versions prior to 0.44.0 and has a CVSS score of 9.9. • Users are urged to upgrade to cpp-httplib version 0.44.0 or later to mitigate risks.

ThreatCluster AI

Timeline

2026-05-29
CVE-2026-45372 published
CVE-2026-45372 details a critical header parsing vulnerability in cpp-httplib, allowing CRLF injection.
Feedly
2026-05-30
Exploit details reported
Exploit-Intel published details on CVE-2026-45372, emphasizing the risk of HTTP-level attacks.
exploit-intel.com

Community

Browse all →