High severity7.4NVD Advisory· Published Mar 27, 2026· Updated Apr 1, 2026
CVE-2026-33745
CVE-2026-33745
Description
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.39.0, the cpp-httplib HTTP client forwards stored Basic Auth, Bearer Token, and Digest Auth credentials to arbitrary hosts when following cross-origin HTTP redirects (301/302/307/308). A malicious or compromised server can redirect the client to an attacker-controlled host, which then receives the plaintext credentials in the Authorization header. Version 0.39.0 fixes the issue.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/yhirose/cpp-httplib/security/advisories/GHSA-6hrp-7fq9-3qv2nvdExploitMitigationVendor Advisory
News mentions
0No linked articles in our index yet.