VDB
CVE-2026-22776
CVE-2026-22776
PUBLISHED
CVSS 8.699999809265137 HIGH
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to version 0.30.1, a Denial of Service (DoS) vulnerability exists in cpp-httplib due to the unsafe handling of compressed HTTP request bodies (Content-Encoding: gzip, br, etc.). The library validates the payload_max_length against the compressed data size received from the network, but does not limit the size of the decompressed data stored in memory.
EPSS 0.37% · 29.6th percentile
Risk Scores
CVSS 4.0
8.699999809265137
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
EPSS Score
0.37%
29.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| yhirose | cpp-httplib | < 0.30.1, 0, < 0.30.1 |
Timeline
- Jan 9, 2026 CVE ID Reserved
- Jan 12, 2026 CVE Published
- Jan 12, 2026 CVE Updated
- Jan 12, 2026 PoC Published
- Jan 12, 2026 PoC Published
- Jan 12, 2026 PoC Published
- Jan 12, 2026 PoC Published
- Jan 13, 2026 EPSS Score
- Jan 16, 2026 EPSS Score
- Jan 19, 2026 EPSS Score
- Jan 23, 2026 EPSS Score
- Jan 26, 2026 EPSS Score