CVE-2026-29076Disclosure(yhirose / cpp-httplib)

LOWCVSS 5.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch yhirose cpp-httplib systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to version 0.37.0, cpp-httplib uses std::regex (libstdc++) to parse RFC 5987 encoded filename* values in multipart Content-Disposition headers. The regex engine in libstdc++ implements backtracking via deep recursion, consuming one stack frame per input character. An attacker can send a single HTTP POST request with a crafted filename* parameter that causes uncontrolled stack growth, resulting in a stack overflow (SIGSEGV) that crashes the server process. This issue has been patched in version 0.37.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-674CWE-1333

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cpp-httplib

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-03-07); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
cpp-httplib

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-03-07: 2Mentions · 2026-03-10: 1Mentions · 2026-03-20: 1Mentions · 2026-03-21: 1Patch / Workaround · 2026-03-20: 1Patch / Workaround · 2026-03-21: 1Technical Details · 2026-03-07: 2Technical Details · 2026-03-10: 1Technical Details · 2026-03-20: 1Technical Details · 2026-03-21: 103-0703-1003-2003-21
Signal classification3 categories
Disclosure
240.0%
Patch
240.0%
General
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-072
Disclosure2
2026-03-101
General1
2026-03-201
Patch1
2026-03-211
Patch1
Full discourse5 posts
  • ThreatCluster@threatcluster
    Patch

    Fedora 42-44 patch critical DoS flaws in cpp-httplib, including CVE-2026-29076 and CVE-2026-31870. Users should update to 0.37.0/0.37.1 to prevent service disruption. #infosec https://threatcluster.io/cluster/critical-denial-of-service-vulnerabilities-in-cpp-httplib-af-22769d3e

    Post summary

    The post announces that Fedora 42‑44 has patched critical DoS vulnerabilities in cpp‑httplib (CVE‑2026‑29076 & CVE‑2026‑31870) and advises users to upgrade to versions 0.37.0/0.37.1 to avoid service disruption.

    0001076
    105 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-29076 Denial of Service via Stack Overflow in cpp-httplib Regex Parsing Before 0.37.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-29076

    Post summary

    The text announces a denial‑of‑service vulnerability in cpp‑httplib caused by a stack overflow during regex parsing in versions older than 0.37.0.

    0000138
    4.0K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Critical security advisory for #Fedora 44: The cpp-httplib package has been updated to version 0.37.1 to address multiple high-severity DoS vulnerabilities (CVE-2026-31870, CVE-2026-29076, CVE-2026-28435). Read more:👉 https://tinyurl.com/ybtpw3xm #Security https://t.co/P7XApjmMQO

    Post summary

    The advisory announces an update to cpp‑httplib in Fedora 44 to fix several high‑severity DoS CVEs, with no PoC, exploit, or active exploitation details provided.

    0000083
    1.5K followersView on X
  • DailyCVE@dailycve
    General

    🟠 cpp-httplib, Uncontrolled Recursion, #CVE-2026-29076 (Medium) https://dailycve.com/cpp-httplib-uncontrolled-recursion-cve-2026-29076-medium/

    Post summary

    The text announces CVE-2026-29076 against cpp-httplib with a medium severity rating, but provides no details on PoCs, exploitation, patches, or active attacks.

    0000040
    167 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-29076 cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to version 0.37.0, cpp-httplib uses std::regex (libstdc++) to parse RFC 5987 e… https://www.cve.org/CVERecord?id=CVE-2026-29076

    Post summary

    This text announces CVE‑2026‑29076, noting that cpp‑httplib’s use of std::regex to parse RFC 5987 before v0.37.0 presents a vulnerability, but it provides no PoC, exploit, or patch details.

    0000091
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appyhirosecpp-httplib---

Explore more