← Vulnerability feed

Vulnerability record · CVE-2026-54919 · published 10 July 2026

CVE-2026-54919: Yhirose cpp-httplib improper certificate validation vulnerability

YYhirose · Cpp Httplib

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. In affected Mbed TLS backend versions from 0.31.0 through 0.46.1 and wolfSSL backend versions from 0.33.0 through 0.46.1, when cpp-httplib is built with CPPHTTPLIB_MBEDTLS_SUPPORT or CPPHTTPLIB_WOLFSSL_SUPPORT and a client connects to an IP-literal host with server certificate verification enabled, SSLClient and Client in HTTPS mode skip certificate chain validation and WebSocketClient on the Mbed TLS backend skips verification altogether, allowing a man-in-the-middle attacker positioned to intercept traffic to present a crafted certificate and read or modify the traffic. This issue is fixed in version 0.47.0.

7.4 CVSS 3.1 High EPSS 0.26% · top 83.6% CWE-295 · Improper certificate validation
7.4CVSS 3.1 base score
0.26%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References
14 Jul 2026Last modified by NVD

Description

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. In affected Mbed TLS backend versions from 0.31.0 through 0.46.1 and wolfSSL backend versions from 0.33.0 through 0.46.1, when cpp-httplib is built with CPPHTTPLIB_MBEDTLS_SUPPORT or CPPHTTPLIB_WOLFSSL_SUPPORT and a client connects to an IP-literal host with server certificate verification enabled, SSLClient and Client in HTTPS mode skip certificate chain validation and WebSocketClient on the Mbed TLS backend skips verification altogether, allowing a man-in-the-middle attacker positioned to intercept traffic to present a crafted certificate and read or modify the traffic. This issue is fixed in version 0.47.0.

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-54919 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2026-45372Yhirose cpp-httplib http request smuggling vulnerabilitycpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.44.0, when cpp-httplib's server parses an incoming reque…EPSS 0.41%9.8CVE-2025-66570Yhirose cpp-httplib authentication bypass by spoofing vulnerabilitycpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.27.0, a vulnerability allows attacker-controlled HTTP he…EPSS 0.33%8.7CVE-2026-46527Yhirose cpp-httplib null pointer dereference vulnerabilitycpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.44.0, When the server has called Server::set_trusted_pro…EPSS 0.49%8.7CVE-2026-22776Yhirose cpp-httplib vulnerabilitycpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to version 0.30.1, a Denial of Service (DoS) vulnerability ex…EPSS 0.40%8.1CVE-2026-32627Yhirose cpp-httplib improper certificate validation vulnerabilitycpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.37.2, when a cpp-httplib client is configured with a pro…EPSS 0.25%7.7CVE-2026-21428Yhirose cpp-httplib vulnerabilitycpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to version 0.30.0, the ``write_headers`` function does not ch…EPSS 0.41%7.5CVE-2026-45352Yhirose cpp-httplib improper input validation vulnerabilitycpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.43.4, negative chunk-size in chunked Transfer-Encoding c…EPSS 0.49%7.5CVE-2026-31870Yhirose cpp-httplib vulnerabilitycpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.37.1, when a cpp-httplib client uses the streaming API (…EPSS 0.55%

Source: NIST National Vulnerability Database (record CVE-2026-54919), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.