CVE-2026-28435: Yhirose Cpp-Httplib
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.35.0, cpp-httplib (httplib.h) does not enforce Server::set_payload_max_length() on the decompressed request body when using HandlerWithContentReader (streaming ContentReader) with Content-Encoding: gzip (or other supported encodings). A small compressed payload can expand beyond the configured payload limit and be processed by the application, enabling a payload size limit bypass and potential denial of service (CPU/memory exhaustion). This vulnerability is fixed in 0.35.0.
Affected products
- Yhirose Cpp-Httplib: before 0.35.0 (fixed in 0.35.0)
Published 2026-03-04. Last modified 2026-06-17.