icon

We found results for “

CVE-2025-66577

Good to know:

icon
icon

Date: December 5, 2025

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.27.0, a vulnerability allows attacker-controlled HTTP headers to influence server-visible metadata, logging, and authorization decisions. An attacker can supply X-Forwarded-For or X-Real-IP headers which get accepted unconditionally by get_client_ip() in docker/main.cc, causing access and error logs (nginx_access_logger / nginx_error_logger) to record spoofed client IPs (log poisoning / audit evasion). This vulnerability is fixed in 0.27.0.

Severity Score

Severity Score

Weakness Type (CWE)

Improper Output Neutralization for Logs

CWE-117

Reliance on Untrusted Inputs in a Security Decision

CWE-807

Top Fix

icon

Upgrade Version

Upgrade to version cpp-httplib - 0.27.0;https://github.com/yhirose/cpp-httplib.git - v0.27.0

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): LOW
Integrity (I): LOW
Availability (A): HIGH

Do you need more information?

Contact Us