CVE-2025-0825
cpp-httplib version v0.17.3 through v0.18.3 fails to filter CRLF characters ("\r\n") when those are prefixed with a null byte. This enables attackers to exploit CRLF injection that could further lead to HTTP Response Splitting, XSS, and more.
Vendor
Product
CWE
Yayın Tarihi
2025-02-04 15:15:19
Güncelleme
2025-08-04 15:06:24
Source Identifier
596c5446-0ce5-4ba2-aa66-48b3b757a647
KEV Date Added
-