CVE-2020-11709
Severity CVSS v4.0:
Pending analysis
Type:
CWE-74
Injection
Publication date:
12/04/2020
Last modified:
05/08/2025
Description
cpp-httplib through 0.5.8 does not filter \r\n in parameters passed into the set_redirect and set_header functions, which creates possibilities for CRLF injection and HTTP response splitting in some specific contexts.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:yhirose:cpp-httplib:*:*:*:*:*:*:*:* | 0.5.8 (including) |
To consult the complete list of CPE names with products and versions, see this page



