CVE Explorer
CVE-2026-22776
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to version 0.30.1, a Denial of Service (DoS) vulnerability exists in cpp-httplib due to the unsafe handling of compressed HTTP request bodies (Content-Encoding: gzip, br, etc.). The library validates the payload_max_length against the compressed data size received from the network, but does not limit the size of the decompressed data stored in memory.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"cpp-httplib","vendor":"yhirose","versions":[{"status":"affected","version":"< 0.30.1"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:8fce3fb705f055690e54e97b46517e860cbd4f332fab31e1dc52a0af63859427 · sha256:3c84ed6f77dc329c… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":8.7,"baseSeverity":"HIGH","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:8fce3fb705f055690e54e97b46517e860cbd4f332fab31e1dc52a0af63859427 · sha256:3c84ed6f77dc329c… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-409","description":"CWE-409: Improper Handling of Highly Compressed Data (Data Amplification)","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:8fce3fb705f055690e54e97b46517e860cbd4f332fab31e1dc52a0af63859427 · sha256:3c84ed6f77dc329c… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/yhirose/cpp-httplib/commit/2e2e47bab1ae6a853476eecbc4bf279dd1fef792","tags":["x_refsource_MISC"],"url":"https://github.com/yhirose/cpp-httplib/commit/2e2e47bab1ae6a853476eecbc4bf279dd1fef792"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:8fce3fb705f055690e54e97b46517e860cbd4f332fab31e1dc52a0af63859427 · sha256:3c84ed6f77dc329c… · /containers/cna/references/1
{"name":"https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-h934-98h4-j43q","tags":["x_refsource_CONFIRM"],"url":"https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-h934-98h4-j43q"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:8fce3fb705f055690e54e97b46517e860cbd4f332fab31e1dc52a0af63859427 · sha256:3c84ed6f77dc329c… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.