CVE-2026-31870

Description

A flaw was found in cpp-httplib. A remote attacker, acting as a malicious server or through a man-in-the-middle position, can send a specially crafted HTTP response with a malformed Content-Length header. This lack of input validation and exception handling causes the client application to crash, resulting in a Denial of Service (DoS).

Statement

This IMPORTANT vulnerability in cpp-httplib allows a remote attacker, acting as a malicious server or through a man-in-the-middle position, to trigger a denial of service in client applications utilizing the streaming API. The flaw occurs due to insufficient input validation of the Content-Length header, leading to an application crash. No authentication or user interaction is required for successful exploitation. This affects Red Hat Community Projects that incorporate cpp-httplib, such as those in EPEL and Fedora.

Understanding the Weakness (CWE)

Other

Technical Impact: Varies by Context

Frequently Asked Questions

Want to get errata notifications? Sign up here.