CVE-2026-31870
Description
A flaw was found in cpp-httplib. A remote attacker, acting as a malicious server or through a man-in-the-middle position, can send a specially crafted HTTP response with a malformed Content-Length header. This lack of input validation and exception handling causes the client application to crash, resulting in a Denial of Service (DoS).
Statement
This IMPORTANT vulnerability in cpp-httplib allows a remote attacker, acting as a malicious server or through a man-in-the-middle position, to trigger a denial of service in client applications utilizing the streaming API. The flaw occurs due to insufficient input validation of the Content-Length header, leading to an application crash. No authentication or user interaction is required for successful exploitation. This affects Red Hat Community Projects that incorporate cpp-httplib, such as those in EPEL and Fedora.
Understanding the Weakness (CWE)
Other
Technical Impact: Varies by Context
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.