CVE-2026-31870Patch(yhirose / cpp-httplib)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch yhirose cpp-httplib systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.37.1, when a cpp-httplib client uses the streaming API (httplib::stream::Get, httplib::stream::Post, etc.), the library calls std::stoull() directly on the Content-Length header value received from the server with no input validation and no exception handling. std::stoull throws std::invalid_argument for non-numeric strings and std::out_of_range for values exceeding ULLONG_MAX. Since nothing catches these exceptions, the C++ runtime calls std::terminate(), which kills the process with SIGABRT. Any server the client connects to — including servers reached via HTTP redirects, third-party APIs, or man-in-the-middle positions can crash the client application with a single HTTP response. No authentication is required. No interaction from the end user is required. The crash is deterministic and immediate. This vulnerability is fixed in 0.37.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-248

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cpp-httplib

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-03-12); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
cpp-httplib

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-12: 1Mentions · 2026-03-20: 1Mentions · 2026-03-21: 1Patch / Workaround · 2026-03-20: 1Patch / Workaround · 2026-03-21: 1Technical Details · 2026-03-12: 1Technical Details · 2026-03-20: 1Technical Details · 2026-03-21: 103-1203-2003-21
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-121
Disclosure1
2026-03-201
Patch1
2026-03-211
Patch1
Full discourse3 posts
  • ThreatCluster@threatcluster
    Patch

    Fedora 42-44 patch critical DoS flaws in cpp-httplib, including CVE-2026-29076 and CVE-2026-31870. Users should update to 0.37.0/0.37.1 to prevent service disruption. #infosec https://threatcluster.io/cluster/critical-denial-of-service-vulnerabilities-in-cpp-httplib-af-22769d3e

    Post summary

    The message reports that Fedora 42-44 have patched critical DoS vulnerabilities in cpp-httplib (CVE-2026-29076, CVE-2026-31870) and urges users to upgrade to 0.37.0/0.37.1. No exploit, PoC, or active usage details are provided.

    0001076
    105 followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Critical security advisory for #Fedora 44: The cpp-httplib package has been updated to version 0.37.1 to address multiple high-severity DoS vulnerabilities (CVE-2026-31870, CVE-2026-29076, CVE-2026-28435). Read more:👉 https://tinyurl.com/ybtpw3xm #Security https://t.co/P7XApjmMQO

    Post summary

    The advisory informs users that Fedora 44’s cpp‑httplib package has been upgraded to 0.37.1 to fix three high‑severity DoS flaws (CVE‑2026‑31870, CVE‑2026‑29076, CVE‑2026‑28435), with no mention of PoC, exploit, or active attacks.

    0000083
    1.5K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-31870 cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.37.1, when a cpp-httplib client uses the streaming API (httplib::stream::… https://www.cve.org/CVERecord?id=CVE-2026-31870

    Post summary

    The text announces a vulnerability in cpp‑httplib before version 0.37.1 affecting the streaming API, providing technical details but no PoC, exploit, or patch information.

    00000194
    56.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appyhirosecpp-httplib---

Explore more