Upstream information

CVE-2025-0825 at MITRE

Description

cpp-httplib version v0.17.3 through v0.18.3 fails to filter CRLF characters ("\r\n") when those are prefixed with a null byte. This enables attackers to exploit CRLF injection that could further lead to HTTP Response Splitting, XSS, and more.

SUSE information

Overall state of this security issue: Does not affect SUSE products

This issue is currently rated as having moderate severity.

CVSS v4 Scores
  CNA (596c5446-0ce5-4ba2-aa66-48b3b757a647)
Base Score 6.9
Vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Attack Vector Network
Attack Complexity Low
Attack Requirements None
Privileges Required None
User Interaction Active
Vulnerable System Confidentiality Impact None
Vulnerable System Integrity Impact High
Vulnerable System Availability Impact None
Subsequent System Confidentiality Impact None
Subsequent System Integrity Impact None
Subsequent System Availability Impact None
CVSSv4 Version 4.0
SUSE Bugzilla entry: 1236790 [NEW]

No SUSE Security Announcements cross referenced.

List of released packages

Product(s) Fixed package version(s) References
SUSE Package Hub 15 SP6
  • cpp-httplib-devel >= 0.12.5-bp156.2.3.1
  • libcpp-httplib0_12 >= 0.12.5-bp156.2.3.1
Patchnames:
openSUSE-2025-63
openSUSE Leap 15.6
  • cpp-httplib-devel >= 0.12.5-bp156.2.3.1
  • libcpp-httplib0_12 >= 0.12.5-bp156.2.3.1
Patchnames:
openSUSE-2025-63


SUSE Timeline for this CVE

CVE page created: Tue Feb 4 18:01:32 2025
CVE page last modified: Mon Feb 17 20:07:42 2025