CVE-2025-53629: Yhirose Cpp-Httplib
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.23.0, incoming requests using Transfer-Encoding: chunked in the header can allocate memory arbitrarily in the server, potentially leading to its exhaustion. This vulnerability is fixed in 0.23.0. NOTE: This vulnerability is related to CVE-2025-53628.
Affected products
- Yhirose Cpp-Httplib: before 0.23.0 (fixed in 0.23.0)
Published 2025-07-10. Last modified 2026-06-17.