Pop-Up Thingie

>>> Magnum BBS <<<
  • Home
  • Forum
  • Files
  • Log in

  1. Forum
  2. Usenet
  3. LINUX.DEBIAN.BUGS.RC
  • Bug#1109340: cpp-httplib: CVE-2025-52887 CVE-2025-53628 CVE-2025-53629

    From =?UTF-8?Q?Moritz_M=C3=BChlenhoff?=@21:1/5 to All on Tue Jul 15 14:40:01 2025
    Package: cpp-httplib
    X-Debbugs-CC: [email protected]
    Severity: grave
    Tags: security

    Hi,

    The following vulnerabilities were published for cpp-httplib.

    CVE-2025-52887[0]:
    | cpp-httplib is a C++11 single-file header-only cross platform
    | HTTP/HTTPS library. In version 0.21.0, when many http headers fields
    | are passed in, the library does not limit the number of headers, and
    | the memory associated with the headers will not be released when the
    | connection is disconnected. This leads to potential exhaustion of
    | system memory and results in a server crash or unresponsiveness.
    | Version 0.22.0 contains a patch for the issue.

    https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-xjhg-gf59-p92h https://github.com/yhirose/cpp-httplib/commit/28dcf379e82a2cdb544d812696a7fd46067eb7f9 (v0.22.0)

    This might be specific to 0.21, but needs confirmation.

    CVE-2025-53628[1]:
    | cpp-httplib is a C++11 single-file header-only cross platform
    | HTTP/HTTPS library. Prior to 0.20.1, cpp-httplib does not have a
    | limit for a unique line, permitting an attacker to explore this to
    | allocate memory arbitrarily. This vulnerability is fixed in 0.20.1.
    | NOTE: This vulnerability is related to CVE-2025-53629.

    https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-j6p8-779x-p5pw https://github.com/yhirose/cpp-httplib/commit/7b752106ac42bd5b907793950d9125a0972c8e8e (v0.20.1)

    CVE-2025-53629[2]:
    | cpp-httplib is a C++11 single-file header-only cross platform
    | HTTP/HTTPS library. Prior to 0.23.0, incoming requests using
    | Transfer-Encoding: chunked in the header can allocate memory
    | arbitrarily in the server, potentially leading to its exhaustion.
    | This vulnerability is fixed in 0.23.0. NOTE: This vulnerability is
    | related to CVE-2025-53628.

    https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-qjmq-h3cc-qv6w https://github.com/yhirose/cpp-httplib/commit/17ba303889b8d4d719be3879a70639ab653efb99 (v0.23.0)


    If you fix the vulnerabilities please also make sure to include the
    CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

    For further information see:

    [0] https://security-tracker.debian.org/tracker/CVE-2025-52887
    https://www.cve.org/CVERecord?id=CVE-2025-52887
    [1] https://security-tracker.debian.org/tracker/CVE-2025-53628
    https://www.cve.org/CVERecord?id=CVE-2025-53628
    [2] https://security-tracker.debian.org/tracker/CVE-2025-53629
    https://www.cve.org/CVERecord?id=CVE-2025-53629

    Please adjust the affected versions in the BTS as needed.

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From Debian Bug Tracking System@21:1/5 to All on Wed Jul 16 11:50:01 2025
    Processing control commands:

    found -1 0.18.7-1
    Bug #1109340 [cpp-httplib] cpp-httplib: CVE-2025-52887 CVE-2025-53628 CVE-2025-53629
    There is no source info for the package 'cpp-httplib' at version '0.18.7-1' with architecture ''
    Unable to make a source version for version '0.18.7-1'
    Marked as found in versions 0.18.7-1.

    --
    1109340: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1109340
    Debian Bug Tracking System
    Contact [email protected] with problems

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • Who's Online

  • Recent Visitors

    • Krenn
      Sun Jun 7 03:07:26 2026
      from Sydney, Nsw via Telnet
    • Krenn
      Sun Jun 7 01:30:12 2026
      from Sydney, Nsw via Telnet
    • Centurion
      Sat Jun 6 23:27:30 2026
      from Berea, Ohio via Telnet
    • Ab Cadd
      Sat Jun 6 15:42:53 2026
      from Sheboygan, Wi via Telnet
    • Centurion
      Sat Jun 6 15:32:28 2026
      from Berea, Ohio via Telnet
    • Krenn
      Sat Jun 6 11:38:56 2026
      from Sydney, Nsw via Telnet
    • Furryboy
      Sat Jun 6 10:56:29 2026
      from Romania, Galati via SSH
    • Centurion
      Fri Jun 5 22:28:01 2026
      from Berea, Ohio via Telnet
  • System Info

    Sysop: Keyop
    Location: Huddersfield, West Yorkshire, UK
    Users: 715
    Nodes: 16 (2 / 14)
    Uptime: 159:57:03
    Calls: 12,094
    Calls today: 2
    Files: 15,000
    Messages: 6,517,761

© >>> Magnum BBS <<<, 2026