CVE Explorer
CVE-2026-54919
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. In affected Mbed TLS backend versions from 0.31.0 through 0.46.1 and wolfSSL backend versions from 0.33.0 through 0.46.1, when cpp-httplib is built with CPPHTTPLIB_MBEDTLS_SUPPORT or CPPHTTPLIB_WOLFSSL_SUPPORT and a client connects to an IP-literal host with server certificate verification enabled, SSLClient and Client in HTTPS mode skip certificate chain validation and WebSocketClient on the Mbed TLS backend skips
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"cpp-httplib","vendor":"yhirose","versions":[{"status":"affected","version":">= 0.31.0, < 0.47.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:80907bb17678d09628cdeb6a15eac118420f4b194ecf3da77d69bfc41c4e8246 · sha256:015921455daa597e… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":7.4,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:80907bb17678d09628cdeb6a15eac118420f4b194ecf3da77d69bfc41c4e8246 · sha256:015921455daa597e… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-295","description":"CWE-295: Improper Certificate Validation","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:80907bb17678d09628cdeb6a15eac118420f4b194ecf3da77d69bfc41c4e8246 · sha256:015921455daa597e… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"name":"https://github.com/yhirose/cpp-httplib/commit/fa981cedae004ea9d946f1392b9dec22fac6fee6","tags":["x_refsource_MISC"],"url":"https://github.com/yhirose/cpp-httplib/commit/fa981cedae004ea9d946f1392b9dec22fac6fee6"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:80907bb17678d09628cdeb6a15eac118420f4b194ecf3da77d69bfc41c4e8246 · sha256:015921455daa597e… · /containers/cna/references/1
{"name":"https://github.com/yhirose/cpp-httplib/releases/tag/v0.47.0","tags":["x_refsource_MISC"],"url":"https://github.com/yhirose/cpp-httplib/releases/tag/v0.47.0"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:80907bb17678d09628cdeb6a15eac118420f4b194ecf3da77d69bfc41c4e8246 · sha256:015921455daa597e… · /containers/cna/references/2
{"name":"https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-8ffh-4p95-g3p2","tags":["x_refsource_CONFIRM"],"url":"https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-8ffh-4p95-g3p2"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:80907bb17678d09628cdeb6a15eac118420f4b194ecf3da77d69bfc41c4e8246 · sha256:015921455daa597e… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.