cve/2023/CVE-2023-26130.md
2024-06-22 09:37:59 +00:00

1.1 KiB

CVE-2023-26130

Description

Versions of the package yhirose/cpp-httplib before 0.12.4 are vulnerable to CRLF Injection when untrusted user input is used to set the content-type header in the HTTP .Patch, .Post, .Put and .Delete requests. This can lead to logical errors and other misbehaviors.

Note: This issue is present due to an incomplete fix for CVE-2020-11709.

POC

Reference

Github