CVE-2026-21428

Description

A flaw was found in cpp-httplib, a C++ HTTP/HTTPS library. A remote attacker can exploit this vulnerability by injecting carriage return and line feed characters into user-supplied headers. This allows the attacker to add extra headers, modify the request body, and potentially trigger a Server-Side Request Forgery attack, which can be used to make a server send requests to an unintended location.

Statement

This vulnerability is rated IMPORTANT as it allows remote attackers to perform Server-Side Request Forgery attacks to locations outside the scope of cpp-httplib by injecting carriage return and line feed characters into user-supplied headers. This affects applications utilizing the cpp-httplib library in Red Hat Community Projects such as Fedora and EPEL, where the library is used to process untrusted HTTP headers.

Understanding the Weakness (CWE)

Integrity

Technical Impact: Modify Application Data

Frequently Asked Questions

Want to get errata notifications? Sign up here.