Pop-Up Thingie

>>> Magnum BBS <<<
  • Home
  • Forum
  • Files
  • Log in

  1. Forum
  2. Usenet
  3. LINUX.DEBIAN.BUGS.RC
  • Bug#1109340: cpp-httplib: CVE-2025-52887 CVE-2025-53628 CVE-2025-53629

    From =?UTF-8?Q?Moritz_M=C3=BChlenhoff?=@21:1/5 to All on Tue Jul 15 14:40:01 2025
    Package: cpp-httplib
    X-Debbugs-CC: [email protected]
    Severity: grave
    Tags: security

    Hi,

    The following vulnerabilities were published for cpp-httplib.

    CVE-2025-52887[0]:
    | cpp-httplib is a C++11 single-file header-only cross platform
    | HTTP/HTTPS library. In version 0.21.0, when many http headers fields
    | are passed in, the library does not limit the number of headers, and
    | the memory associated with the headers will not be released when the
    | connection is disconnected. This leads to potential exhaustion of
    | system memory and results in a server crash or unresponsiveness.
    | Version 0.22.0 contains a patch for the issue.

    https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-xjhg-gf59-p92h https://github.com/yhirose/cpp-httplib/commit/28dcf379e82a2cdb544d812696a7fd46067eb7f9 (v0.22.0)

    This might be specific to 0.21, but needs confirmation.

    CVE-2025-53628[1]:
    | cpp-httplib is a C++11 single-file header-only cross platform
    | HTTP/HTTPS library. Prior to 0.20.1, cpp-httplib does not have a
    | limit for a unique line, permitting an attacker to explore this to
    | allocate memory arbitrarily. This vulnerability is fixed in 0.20.1.
    | NOTE: This vulnerability is related to CVE-2025-53629.

    https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-j6p8-779x-p5pw https://github.com/yhirose/cpp-httplib/commit/7b752106ac42bd5b907793950d9125a0972c8e8e (v0.20.1)

    CVE-2025-53629[2]:
    | cpp-httplib is a C++11 single-file header-only cross platform
    | HTTP/HTTPS library. Prior to 0.23.0, incoming requests using
    | Transfer-Encoding: chunked in the header can allocate memory
    | arbitrarily in the server, potentially leading to its exhaustion.
    | This vulnerability is fixed in 0.23.0. NOTE: This vulnerability is
    | related to CVE-2025-53628.

    https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-qjmq-h3cc-qv6w https://github.com/yhirose/cpp-httplib/commit/17ba303889b8d4d719be3879a70639ab653efb99 (v0.23.0)


    If you fix the vulnerabilities please also make sure to include the
    CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

    For further information see:

    [0] https://security-tracker.debian.org/tracker/CVE-2025-52887
    https://www.cve.org/CVERecord?id=CVE-2025-52887
    [1] https://security-tracker.debian.org/tracker/CVE-2025-53628
    https://www.cve.org/CVERecord?id=CVE-2025-53628
    [2] https://security-tracker.debian.org/tracker/CVE-2025-53629
    https://www.cve.org/CVERecord?id=CVE-2025-53629

    Please adjust the affected versions in the BTS as needed.

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From Debian Bug Tracking System@21:1/5 to All on Wed Jul 16 11:50:01 2025
    Processing control commands:

    found -1 0.18.7-1
    Bug #1109340 [cpp-httplib] cpp-httplib: CVE-2025-52887 CVE-2025-53628 CVE-2025-53629
    There is no source info for the package 'cpp-httplib' at version '0.18.7-1' with architecture ''
    Unable to make a source version for version '0.18.7-1'
    Marked as found in versions 0.18.7-1.

    --
    1109340: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1109340
    Debian Bug Tracking System
    Contact [email protected] with problems

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • Who's Online

  • Recent Visitors

    • Rixter
      Thu Jul 30 02:32:09 2026
      from Madison, Nc via Telnet
    • Bob Worm
      Wed Jul 29 22:26:45 2026
      from Wales, Uk via Telnet
    • Zenobyte
      Wed Jul 29 21:08:05 2026
      from San Juan, Pr via Telnet
    • Guest
      Wed Jul 29 14:26:54 2026
      from Balkans via Telnet
    • Rixter
      Wed Jul 29 14:18:17 2026
      from Madison, Nc via Telnet
    • Rixter
      Wed Jul 29 02:00:40 2026
      from Madison, Nc via Telnet
    • Centurion
      Tue Jul 28 22:54:59 2026
      from Berea, Ohio via Telnet
    • Bob Worm
      Tue Jul 28 16:01:18 2026
      from Wales, Uk via Telnet
  • System Info

    Sysop: Keyop
    Location: Huddersfield, West Yorkshire, UK
    Users: 741
    Nodes: 16 (2 / 14)
    Uptime: 79:44:09
    Calls: 12,451
    Calls today: 1
    Files: 15,194
    Messages: 6,537,724

© >>> Magnum BBS <<<, 2026