CVE-2020-11709

Severity CVSS v4.0:
Pending analysis
Type:
CWE-74 Injection
Publication date:
12/04/2020
Last modified:
05/08/2025

Description

cpp-httplib through 0.5.8 does not filter \r\n in parameters passed into the set_redirect and set_header functions, which creates possibilities for CRLF injection and HTTP response splitting in some specific contexts.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:yhirose:cpp-httplib:*:*:*:*:*:*:*:* 0.5.8 (including)