CVE-2025-53629: Yhirose Cpp-Httplib

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.23.0, incoming requests using Transfer-Encoding: chunked in the header can allocate memory arbitrarily in the server, potentially leading to its exhaustion. This vulnerability is fixed in 0.23.0. NOTE: This vulnerability is related to CVE-2025-53628.

Affected products

  • Yhirose Cpp-Httplib: before 0.23.0 (fixed in 0.23.0)

Published 2025-07-10. Last modified 2026-06-17.