yhirose.cpp-httplib is vulnerable to CRLF Injection
61
Medium Risk
The library writes HTTP trailer field names and values in write_content_chunked through the DataSink::done_with_trailer path without validating them, unlike other header output paths. When an application reflects untrusted input into chunked-response trailers, carriage-return and line-feed characters pass through unfiltered. This allows HTTP response splitting and can enable cache poisoning, cross-site scripting, or session fixation against clients. The fix validates trailer field names and values and silently skips entries that are not well-formed.
You are affected if you are using a version that falls within the vulnerable range and your application reflects untrusted input into chunked-response trailer fields.
yhirose.cpp-httplib is vulnerable to CRLF Injection in versions 0.12.2 - 0.49.0.
Upgrade the yhirose.cpp-httplib library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant