HomeYhiroseCVE-2020-11709

CVE-2020-11709

HIGH
7.5CVSS
Published: 2020-04-12
Updated: 2025-08-05
AI Analysis

Description

cpp-httplib through 0.5.8 does not filter \r\n in parameters passed into the set_redirect and set_header functions, which creates possibilities for CRLF injection and HTTP response splitting in some specific contexts.

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Attack Vector
network
Complexity
low
Privileges
none
User Action
none
Scope
unchanged
Confidentiality
none
Integrity
high
Availability
none
Weaknesses
CWE-74

Metadata

Primary Vendor
YHIROSE
Published
4/12/2020
Last Modified
8/5/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

yhirose : cpp-httplib

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief