Unrated severityNVD Advisory· Published Jan 12, 2026· Updated Jan 12, 2026
cpp-httplib vulnerable to a denial of service (DOS) using a zip bomb
CVE-2026-22776
Description
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to version 0.30.1, a Denial of Service (DoS) vulnerability exists in cpp-httplib due to the unsafe handling of compressed HTTP request bodies (Content-Encoding: gzip, br, etc.). The library validates the payload_max_length against the compressed data size received from the network, but does not limit the size of the decompressed data stored in memory.
Affected products
1- Range: < 0.30.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/yhirose/cpp-httplib/commit/2e2e47bab1ae6a853476eecbc4bf279dd1fef792mitrex_refsource_MISC
- github.com/yhirose/cpp-httplib/security/advisories/GHSA-h934-98h4-j43qmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.