{"id":"CVE-2025-52887","summary":"cpp-httplib has unlimited number of http header fields, which causes memory leak","details":"cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. In version 0.21.0, when many http headers fields are passed in, the library does not limit the number of headers, and the memory associated with the headers will not be released when the connection is disconnected. This leads to potential exhaustion of system memory and results in a server crash or unresponsiveness. Version 0.22.0 contains a patch for the issue.","aliases":["GHSA-xjhg-gf59-p92h"],"modified":"2026-08-12T15:13:56.970033Z","published":"2025-06-26T14:31:52.092Z","database_specific":{"cwe_ids":["CWE-400"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/52xxx/CVE-2025-52887.json","cna_assigner":"GitHub_M"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/52xxx/CVE-2025-52887.json"},{"type":"ADVISORY","url":"https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-xjhg-gf59-p92h"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-52887"},{"type":"FIX","url":"https://github.com/yhirose/cpp-httplib/commit/28dcf379e82a2cdb544d812696a7fd46067eb7f9"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/yhirose/cpp-httplib","events":[{"introduced":"3a1f379e751ef6555f06c5c1ef367a6fce26722c"},{"fixed":"28dcf379e82a2cdb544d812696a7fd46067eb7f9"}],"database_specific":{"cpe":"cpe:2.3:a:yhirose:cpp-httplib:0.21.0:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0.21.0"},{"last_affected":"0.21.0"}],"source":["CPE_STRING","REFERENCES"]}}],"versions":["0.21.0","= 0.21.0","v0.21.0"],"database_specific":{"vanir_signatures":[{"signature_version":"v1","source":"https://github.com/yhirose/cpp-httplib/commit/28dcf379e82a2cdb544d812696a7fd46067eb7f9","target":{"file":"httplib.h"},"deprecated":false,"digest":{"line_hashes":["275671391591463579219520520614650526839","297383916161159859848780964783816081383","187952879261299001881179846929970812144","108467006016609729936947179732288890854","60437407063666212446384722396188081109","79392757655228775030965665326420554885","224490661419801020594851913768626804333","6545929181602795824567813733300304456","195668060767580618445981164458526445517","282916166251811646021848639583646281735","237015639466640384429116307850737299063","240522512309630831697827857464120036961","63023319149774050960125992398873200987","297398128986816905378546040946489315767","337289218457491915173034727001663527758","242023523799936387776870628063942765801","281335586367702852998984842891947664423","110684756889977617031225251891009789171","172888895135880388131131509848479196575","270125226515358489486528445998419911337","210855358438095199607249721858741902875"],"threshold":0.9},"id":"CVE-2025-52887-c2164cbf","signature_type":"Line"},{"id":"CVE-2025-52887-c782cf8c","signature_type":"Function","signature_version":"v1","source":"https://github.com/yhirose/cpp-httplib/commit/28dcf379e82a2cdb544d812696a7fd46067eb7f9","target":{"file":"httplib.h","function":"read_headers"},"deprecated":false,"digest":{"function_hash":"337178125486439535957185878008304747404","length":725}},{"digest":{"line_hashes":["244555817801813912373752667492877105211","328908995521614501975032834039713335962","222347871147095164020821689313696166393","294892978126976142761233337511089165018","264890639792726382961425057853420409226","6445826477426803153860939004585363110","28570163837484994210360242146308815836","120211105383261912669870357306172856775","257768843338617806296604682044413224828","177128883742143955674719429924762349700"],"threshold":0.9},"id":"CVE-2025-52887-e63cb16c","signature_type":"Line","signature_version":"v1","source":"https://github.com/yhirose/cpp-httplib/commit/28dcf379e82a2cdb544d812696a7fd46067eb7f9","target":{"file":"test/test.cc"},"deprecated":false},{"deprecated":false,"digest":{"function_hash":"91596895803306304005231320572906139632","length":1154},"id":"CVE-2025-52887-f0231070","signature_type":"Function","signature_version":"v1","source":"https://github.com/yhirose/cpp-httplib/commit/28dcf379e82a2cdb544d812696a7fd46067eb7f9","target":{"file":"httplib.h","function":"read_content_chunked"}}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-52887.json","vanir_signatures_modified":"2026-08-12T15:13:56Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}