CVE-2025-0825
Severity CVSS v4.0:
MEDIUM
Type:
CWE-113
Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')
Publication date:
04/02/2025
Last modified:
04/08/2025
Description
cpp-httplib version v0.17.3 through v0.18.3 fails to filter CRLF characters ("\r\n") when those are prefixed with a null byte. This enables attackers to exploit CRLF injection that could further lead to HTTP Response Splitting, XSS, and more.
Impact
Base Score 4.0
6.90
Severity 4.0
MEDIUM
Base Score 3.x
5.30
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:yhirose:cpp-httplib:*:*:*:*:*:*:*:* | 0.17.3 (including) | 0.18.4 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



