CVE-2026-33745Disclosure(yhirose / cpp-httplib)

LOWCVSS 7.4 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.39.0, the cpp-httplib HTTP client forwards stored Basic Auth, Bearer Token, and Digest Auth credentials to arbitrary hosts when following cross-origin HTTP redirects (301/302/307/308). A malicious or compromised server can redirect the client to an attacker-controlled host, which then receives the plaintext credentials in the `Authorization` header. Version 0.39.0 fixes the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cpp-httplib

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
cpp-httplib

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-27: 3Technical Details · 2026-03-27: 303-27
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-33745 cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.39.0, the cpp-httplib HTTP client forwards stored Basic Auth, Bearer Toke… https://www.cve.org/CVERecord?id=CVE-2026-33745

    Post summary

    The text notes that cpp‑httplib before version 0.39.0 forwards stored credentials, indicating a credential exposure vulnerability.

    00010105
    56.9K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-33745 📊 Severity: 7.4 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-33745 #CVE-2026-33745 #CVE #High #CyberSecurity #InfoSec https://t.co/8MpgirfkBX

    Post summary

    A basic CVE alert is posted, listing its identifier, severity score, and general impacted products, with no further technical details, exploitation evidence, or remediation guidance.

    0000026
    123 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-33745 - cpp-httplib Client Leaks Authentication Credentials to Untrusted Hosts on Cross-Origin HTTP Redirect Intel Report: https://ift.tt/PIQzb0q

    Post summary

    The alert announces CVE-2026-33745, describing a credential‑leakage vulnerability that leaks authentication data to untrusted hosts via cross‑origin HTTP redirects, but does not mention any PoC, exploit, patch, or active exploitation.

    0000053
    284 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appyhirosecpp-httplib---

Explore more