CVE-2026-28435Disclosure(yhirose / cpp-httplib)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch yhirose cpp-httplib systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.35.0, cpp-httplib (httplib.h) does not enforce Server::set_payload_max_length() on the decompressed request body when using HandlerWithContentReader (streaming ContentReader) with Content-Encoding: gzip (or other supported encodings). A small compressed payload can expand beyond the configured payload limit and be processed by the application, enabling a payload size limit bypass and potential denial of service (CPU/memory exhaustion). This vulnerability is fixed in 0.35.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400CWE-409

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cpp-httplib

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-03-04); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
cpp-httplib

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-04: 2Mentions · 2026-03-05: 1Mentions · 2026-03-20: 1Patch / Workaround · 2026-03-20: 1Technical Details · 2026-03-04: 1Technical Details · 2026-03-05: 1Technical Details · 2026-03-20: 103-0403-0503-20
Signal classification3 categories
Disclosure
250.0%
General
125.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-042
Disclosure1General1
2026-03-051
Disclosure1
2026-03-201
Patch1
Full discourse4 posts
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Critical security advisory for #Fedora 44: The cpp-httplib package has been updated to version 0.37.1 to address multiple high-severity DoS vulnerabilities (CVE-2026-31870, CVE-2026-29076, CVE-2026-28435). Read more:👉 https://tinyurl.com/ybtpw3xm #Security https://t.co/P7XApjmMQO

    Post summary

    Fedora 44 receives a critical advisory; a new cpp-httplib 0.37.1 update patches three high‑severity DoS CVEs, with no PoC, exploit code, or active exploitation reported.

    0000083
    1.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-28435 Payload Size Limit Bypass in cpp-httplib Prior to 0.35.0 via Decompression https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28435

    Post summary

    The post discloses a payload size limit bypass in cpp-httplib (prior to 0.35.0) via decompression, offering technical detail but no PoC, exploit, or patch information.

    0000066
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-28435 cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.35.0, cpp-httplib (httplib.h) does not enforce Server::set_payload_max_le… https://www.cve.org/CVERecord?id=CVE-2026-28435 ----- Traducción: CVE-2026-28435 cpp… http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-28435, noting that cpp-httplib before version 0.35.0 lacks enforcement of Server payload size, and links to the CVE record for details.

    0000027
    56 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-28435 cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.35.0, cpp-httplib (httplib.h) does not enforce Server::set_payload_max_le… https://www.cve.org/CVERecord?id=CVE-2026-28435

    Post summary

    The message states that cpp-httplib versions prior to 0.35.0 lack enforcement of a payload limit and provides a link to the CVE record, but no additional technical, exploit, or mitigation details.

    00000225
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appyhirosecpp-httplib---

Explore more