CyberRota Analysis
AI-GeneratedThe cpp-httplib library, when configured with Mbed TLS or wolfSSL support, is vulnerable in specific versions where SSL certificate chain validation is bypassed during client connections to IP-literal hosts with server certificate verification enabled. This flaw allows man-in-the-middle attackers to intercept and manipulate traffic by presenting fraudulent certificates. Organizations using affected versions of cpp-httplib for secure communications should prioritize upgrading to version 0.47.0 to mitigate this high-severity risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. In affected Mbed TLS backend versions from 0.31.0 through 0.46.1 and wolfSSL backend versions from 0.33.0 through 0.46.1, when cpp-httplib is built with CPPHTTPLIB_MBEDTLS_SUPPORT or CPPHTTPLIB_WOLFSSL_SUPPORT and a client connects to an IP-literal host with server certificate verification enabled, SSLClient and Client in HTTPS mode skip certificate chain validation and WebSocketClient on the Mbed TLS backend skips verification altogether, allowing a man-in-the-middle attacker positioned to intercept traffic to present a crafted certificate and read or modify the traffic. This issue is fixed in version 0.47.0.
Related CVEs
Other vulnerabilities affecting the same vendor(s)