CVE-2026-21428
Description
A flaw was found in cpp-httplib, a C++ HTTP/HTTPS library. A remote attacker can exploit this vulnerability by injecting carriage return and line feed characters into user-supplied headers. This allows the attacker to add extra headers, modify the request body, and potentially trigger a Server-Side Request Forgery attack, which can be used to make a server send requests to an unintended location.
Statement
This vulnerability is rated IMPORTANT as it allows remote attackers to perform Server-Side Request Forgery attacks to locations outside the scope of cpp-httplib by injecting carriage return and line feed characters into user-supplied headers. This affects applications utilizing the cpp-httplib library in Red Hat Community Projects such as Fedora and EPEL, where the library is used to process untrusted HTTP headers.
Understanding the Weakness (CWE)
Integrity
Technical Impact: Modify Application Data
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.