Cross-Site HTTP Redirect Vulnerability in cpp-httplib by yhirose
CVE-2026-33745
7.4HIGH
What is CVE-2026-33745?
The cpp-httplib library, used for HTTP/HTTPS communication, is vulnerable to a security flaw where it forwards authentication credentials to unintended hosts during cross-origin HTTP redirects. This issue can be exploited by malicious servers capable of redirecting clients, leading to the exposure of sensitive plaintext credentials contained in the 'Authorization' header. Users are advised to upgrade to version 0.39.0 or later to safeguard against this vulnerability.
Affected Version(s)
cpp-httplib < 0.39.0
