HTTP/HTTPS Library Vulnerability in cpp-httplib by Yhirose
CVE-2025-66577
5.3MEDIUM
What is CVE-2025-66577?
The cpp-httplib library prior to version 0.27.0 contains a vulnerability that allows attacker-controlled HTTP headers, specifically X-Forwarded-For and X-Real-IP, to influence server-visible metadata. This misconfiguration can lead to log poisoning, where spoofed client IPs are recorded in access and error logs, potentially enabling audit evasion and affecting authorization decisions.
Affected Version(s)
cpp-httplib < 0.27.0
