PatchSiren cyber security CVE debrief
CVE-2026-46527 yhirose CVE debrief
A denial-of-service vulnerability exists in cpp-httplib prior to version 0.44.0. When a server has configured a non-empty trusted proxy list via Server::set_trusted_proxies(), an attacker can send an HTTP request containing an X-Forwarded-For header with a value that parses to no valid IP segments. This triggers get_client_ip() to call front() on an empty std::vector, resulting in undefined behavior that typically causes abnormal process termination. The vulnerability was published on 2026-05-29 and is rated HIGH severity with a CVSS score of 8.7.
- Vendor
- yhirose
- Product
- cpp-httplib
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-29
- Original CVE updated
- 2026-07-22
- Advisory published
- 2026-05-29
- Advisory updated
- 2026-07-22
Who should care
Organizations running cpp-httplib-based HTTP servers with trusted proxy configurations, particularly those exposed to untrusted client traffic. Developers maintaining C++ HTTP services and security teams monitoring for DoS vulnerabilities in header parsing implementations.
Technical summary
The vulnerability stems from insufficient validation of X-Forwarded-For header parsing results. When Server::set_trusted_proxies() is configured with a non-empty list, the server attempts to extract client IP addresses from X-Forwarded-For headers. If the header value contains no parseable IP segments, the resulting std::vector remains empty. The get_client_ip() function then calls front() on this empty container, invoking undefined behavior per the C++ standard. In practice, this causes process crashes (SIGSEGV or similar), resulting in denial of service. The issue is classified as CWE-476 (NULL Pointer Dereference) though the specific manifestation is undefined behavior on empty container access.
Defensive priority
HIGH
Recommended defensive actions
- Upgrade cpp-httplib to version 0.44.0 or later
- If immediate patching is not possible, validate X-Forwarded-For header format before processing or disable trusted proxy functionality
- Monitor application logs for abnormal terminations that may indicate exploitation attempts
- Enable AddressSanitizer or UndefinedBehaviorSanitizer in testing environments to detect similar issues
Evidence notes
The vulnerability description is sourced from the official GitHub Security Advisory GHSA-hg3g-vrg8-578g, with CVSS vector and weakness classification (CWE-476: NULL Pointer Dereference) provided by NVD. The fix version 0.44.0 is explicitly stated in the advisory.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-46527 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-46527
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-46527 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-46527
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-hg3g-vrg8-578g
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.