CVE-2025-53628HIGH 8.8EPSS p35.1%

CVE-2025-53628CVE-2025-53628

Description

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.20.1, cpp-httplib does not have a limit for a unique line, permitting an attacker to explore this to allocate memory arbitrarily. This vulnerability is fixed in 0.20.1. NOTE: This vulnerability is related to CVE-2025-53629.

Scoring

CVSS 3.18.8 (HIGH)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS0.44% probability of exploitation · percentile 35.1% · 2026-06-19T12:03:05Z
Published2025-07-10
Last modified2025-08-06

Underlying weaknesses· 3

CWE-770CWE-835CWE-444

References

  1. https://github.com/yhirose/cpp-httplib/commit/7b752106ac42bd5b907793950d9125a0972c8e8e
  2. https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-j6p8-779x-p5pw
  3. https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-qjmq-h3cc-qv6w
  4. https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-j6p8-779x-p5pw

3

TypeTargetConfidenceTier
WeaknessInconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')cwe-4440%live
WeaknessAllocation of Resources Without Limits or Throttlingcwe-7700%live
WeaknessLoop with Unreachable Exit Condition ('Infinite Loop')cwe-8350%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2026-45352
CVE
CVE-2026-45372
CVE
CVE-2026-25210
CVE
CVE-2025-66570
CVE
CVE-2026-46527
CVE
CVE-2026-32627
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.