CVE-2026-32627Patch(yhirose / cpp-httplib)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch yhirose cpp-httplib systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.37.2, when a cpp-httplib client is configured with a proxy and set_follow_location(true), any HTTPS redirect it follows will have TLS certificate and hostname verification silently disabled on the new connection. The client will accept any certificate presented by the redirect target — expired, self-signed, or forged — without raising an error or notifying the application. A network attacker in a position to return a redirect response can fully intercept the follow-up HTTPS connection, including any credentials or session tokens in flight. This vulnerability is fixed in 0.37.2.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-295

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cpp-httplib

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Peaked 1d ago at 1 mentions (2026-03-13); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
cpp-httplib

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-13: 1Mentions · 2026-03-16: 1Patch / Workaround · 2026-03-13: 1Patch / Workaround · 2026-03-16: 1Technical Details · 2026-03-13: 1Technical Details · 2026-03-16: 103-1303-16
Signal classification1 categories
Patch
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-32627: HIGH] Vulnerability alert: Prior to cpp-httplib 0.37.2, HTTPS redirect can disable TLS certificate verification. Update to 0.37.2 to fix the security issue.#cve,CVE-2026-32627,#cybersecurity https://cvefind.com/CVE-2026-32627

    Post summary

    An issue in cpp-httplib before version 0.37.2 allows HTTPS redirects to disable TLS certificate verification. Users are advised to upgrade to 0.37.2 to remediate the problem.

    0000036
    601 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-32627 cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.37.2, when a cpp-httplib client is configured with a proxy and set_follow… https://www.cve.org/CVERecord?id=CVE-2026-32627

    Post summary

    CVE-2026-32627 is a vulnerability in cpp-httplib that exists in versions before 0.37.2, and updating to 0.37.2 or later resolves the issue.

    00000163
    56.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appyhirosecpp-httplib---

Explore more