CVE-2025-46728: cpp-httplib has Unbounded Memory Allocation in Chunked/No-Length Requests
cpp-httplib is a C++ header-only HTTP/HTTPS server and client library. Prior to version 0.20.1, the library fails to enforce configured size limits on incoming request bodies when Transfer-Encoding: chunked is used or when no Content-Length header is provided. A remote attacker can send a chunked request without the terminating zero-length chunk, causing uncontrolled memory allocation on the server. This leads to potential exhaustion of system memory and results in a server crash or unresponsiveness. Version 0.20.1 fixes the issue by enforcing limits during parsing. If the limit is exceeded at any point during reading, the connection is terminated immediately. A short-term workaround through a Reverse Proxy is available. If updating the library immediately is not feasible, deploy a reverse proxy (e.g., Nginx, HAProxy) in front of the cpp-httplib application. Configure the proxy to enforce maximum request body size limits, thereby stopping excessively large requests before they reach the vulnerable library code.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-46728?
CVE-2025-46728 has a vulnerability severity rating that indicates it allows for potential denial of service attacks due to improper request body size enforcement.
How do I fix CVE-2025-46728?
To fix CVE-2025-46728, update cpp-httplib to version 0.20.1 or later where the vulnerability has been addressed.
What are the risks associated with CVE-2025-46728?
The risks associated with CVE-2025-46728 include the possibility of remote attackers exploiting the vulnerability to send oversized request bodies, potentially causing service disruptions.
Which versions of cpp-httplib are affected by CVE-2025-46728?
CVE-2025-46728 affects all versions of cpp-httplib prior to version 0.20.1.
How does CVE-2025-46728 impact web applications?
CVE-2025-46728 can impact web applications by allowing attackers to bypass size limits on incoming requests, which may lead to denial of service or resource exhaustion.