{"id":"CVE-2026-54919","summary":"cpp-httplib: TLS certificate chain verification bypassed for IP-literal hosts on Mbed TLS and wolfSSL backends","details":"cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. In affected Mbed TLS backend versions from 0.31.0 through 0.46.1 and wolfSSL backend versions from 0.33.0 through 0.46.1, when cpp-httplib is built with CPPHTTPLIB_MBEDTLS_SUPPORT or CPPHTTPLIB_WOLFSSL_SUPPORT and a client connects to an IP-literal host with server certificate verification enabled, SSLClient and Client in HTTPS mode skip certificate chain validation and WebSocketClient on the Mbed TLS backend skips verification altogether, allowing a man-in-the-middle attacker positioned to intercept traffic to present a crafted certificate and read or modify the traffic. This issue is fixed in version 0.47.0.","aliases":["GHSA-8ffh-4p95-g3p2"],"modified":"2026-08-12T16:41:18.000530Z","published":"2026-07-10T16:06:12.848Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-295"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54919.json"},"references":[{"type":"WEB","url":"https://github.com/yhirose/cpp-httplib/releases/tag/v0.47.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54919.json"},{"type":"ADVISORY","url":"https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-8ffh-4p95-g3p2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54919"},{"type":"FIX","url":"https://github.com/yhirose/cpp-httplib/commit/fa981cedae004ea9d946f1392b9dec22fac6fee6"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/yhirose/cpp-httplib","events":[{"introduced":"2867b74f131200979b2b885683a189248d80e0f4"},{"fixed":"fe332fa06bac76a1c6d402c08f414052999347da"},{"fixed":"fa981cedae004ea9d946f1392b9dec22fac6fee6"}],"database_specific":{"cpe":"cpe:2.3:a:yhirose:cpp-httplib:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0.31.0"},{"fixed":"0.47.0"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v0.46.1","v0.46.0","v0.45.1","v0.45.0","v0.44.0","v0.43.4","v0.43.3","v0.43.2","v0.43.1","v0.43.0","v0.42.0","v0.41.0","v0.40.0","v0.39.0","v0.38.0","v0.37.2","v0.37.1","v0.37.0","v0.35.0","v0.34.0","latest","v0.33.1","v0.33.0","v0.32.0","v0.31.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54919.json","vanir_signatures_modified":"2026-08-12T16:41:18Z","vanir_signatures":[{"source":"https://github.com/yhirose/cpp-httplib/commit/fa981cedae004ea9d946f1392b9dec22fac6fee6","target":{"file":"httplib.h","function":"create_session"},"deprecated":false,"digest":{"function_hash":"244798551285005665974849621235618061775","length":723},"id":"CVE-2026-54919-0acb3b4c","signature_type":"Function","signature_version":"v1"},{"digest":{"function_hash":"278031654748316764174191698711485268180","length":3259},"id":"CVE-2026-54919-7490be1b","signature_type":"Function","signature_version":"v1","source":"https://github.com/yhirose/cpp-httplib/commit/fa981cedae004ea9d946f1392b9dec22fac6fee6","target":{"file":"httplib.h","function":"SSLClient::initialize_ssl"},"deprecated":false},{"deprecated":false,"digest":{"function_hash":"307924959219438934718154579632510155064","length":707},"id":"CVE-2026-54919-a055b838","signature_type":"Function","signature_version":"v1","source":"https://github.com/yhirose/cpp-httplib/commit/fa981cedae004ea9d946f1392b9dec22fac6fee6","target":{"file":"httplib.h","function":"setup_client_tls_session"}},{"digest":{"line_hashes":["144921194235625452739821385354802835341","136669814074245045257425544155057133343","27192379669465510473157324134579042988","163399326708726824973930995457521119291","340109743481800934042365662765845019210","101965619034357326525895208379258731858","64381931785564330655444740385590579288","165723333409653731016397456908043763677","81498240525283296808452869204899841338","155183202003457392892155348293958155837","100066848822697791703681449479441291095"],"threshold":0.9},"id":"CVE-2026-54919-b02dfc36","signature_type":"Line","signature_version":"v1","source":"https://github.com/yhirose/cpp-httplib/commit/fa981cedae004ea9d946f1392b9dec22fac6fee6","target":{"file":"test/test.cc"},"deprecated":false},{"signature_version":"v1","source":"https://github.com/yhirose/cpp-httplib/commit/fa981cedae004ea9d946f1392b9dec22fac6fee6","target":{"file":"httplib.h"},"deprecated":false,"digest":{"line_hashes":["212905938389791219969346567129228770860","202799028290577366164548141554788821169","118667971893695426822105552939577440663","60032273545905194150142696140994327529","101269862736788965282517352451002057789","129259446797443897337553839889754385128","62158931682984067047985401833866955204","307571031515548831018520065928885648702","90769778261657241502355293095136283541","254476919160950497784454623115050854315","124608378572964376674227634549596250054","19367668774447732001222073571306021139","68394706757768473660005774846428533823","140201705825498087054549233674519768056","98768426612556983068685011922940091514","25149630267970681269428793359934386521","269997167195884862064214766510865293994","272563558294974482851697352897125068052","3406660882268972728232359478839307605","319106081312209461952365416443855361048","200463488978713143216360649652952135797","214398334343658320078656907866823746822","159294198676799533912096471507418116964","50484886272397233794535172006099325643","266058586670752280522335767189654587033","46941585969860222459798424703601881811","186474517470884106482245279932690725124","31796160102422402338483368576859475711","52873434350248561492832753336681186328"],"threshold":0.9},"id":"CVE-2026-54919-fb617a46","signature_type":"Line"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"}]}