cvedb.io
CVE-2026-28435
HIGH · CVSS 7.5
EPSS exploitation probability: 0%
Published 2026-03-04T20:16:19.983 · Last modified 2026-06-17T10:28:38.460

Summary

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.35.0, cpp-httplib (httplib.h) does not enforce Server::set_payload_max_length() on the decompressed request body when using HandlerWithContentReader (streaming ContentReader) with Content-Encoding: gzip (or other supported encodings). A small compressed payload can expand beyond the configured payload limit and be processed by the application, enabling a payload size limit bypass and potential denial of service (CPU/memory exhaustion). This vulnerability is fixed in 0.35.0.

Affected products

yhirose — cpp-httplib

Does this affect you?

Add your gear to cvedb and we'll alert you only when yhirose ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.