CVE-2025-53628HIGH 8.8EPSS p35.1%
CVE-2025-53628CVE-2025-53628
Description
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.20.1, cpp-httplib does not have a limit for a unique line, permitting an attacker to explore this to allocate memory arbitrarily. This vulnerability is fixed in 0.20.1. NOTE: This vulnerability is related to CVE-2025-53629.
Scoring
| CVSS 3.1 | 8.8 (HIGH) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| EPSS | 0.44% probability of exploitation · percentile 35.1% · 2026-06-19T12:03:05Z |
| Published | 2025-07-10 |
| Last modified | 2025-08-06 |
Underlying weaknesses· 3
References
- https://github.com/yhirose/cpp-httplib/commit/7b752106ac42bd5b907793950d9125a0972c8e8e
- https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-j6p8-779x-p5pw
- https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-qjmq-h3cc-qv6w
- https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-j6p8-779x-p5pw
3
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')cwe-444 | 0% | live |
| Weakness | Allocation of Resources Without Limits or Throttlingcwe-770 | 0% | live |
| Weakness | Loop with Unreachable Exit Condition ('Infinite Loop')cwe-835 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.