CVE-2026-22776: cpp-httplib vulnerable to a denial of service (DOS) using a zip bomb

Published Jan 12, 2026
·
Updated

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to version 0.30.1, a Denial of Service (DoS) vulnerability exists in cpp-httplib due to the unsafe handling of compressed HTTP request bodies (Content-Encoding: gzip, br, etc.). The library validates the payloadmaxlength against the compressed data size received from the network, but does not limit the size of the decompressed data stored in memory.

Affected Software

2 affected components
cpp-httplib<0.30.1
Yhirose Cpp-httplib<0.30.1

Event History

Jan 12, 2026
CVE Published
via MITRE·06:18 PM
Data Sourced
via MITRE·06:18 PM
DescriptionWeakness
Data Sourced
via NVD·07:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Apr 12, 58019
Event
via FIRST·12:53 AM

Frequently Asked Questions

1

What is the severity of CVE-2026-22776?

CVE-2026-22776 is classified as a high-severity Denial of Service (DoS) vulnerability.

2

How do I fix CVE-2026-22776?

To fix CVE-2026-22776, upgrade to cpp-httplib version 0.30.1 or later.

3

What causes CVE-2026-22776?

CVE-2026-22776 is caused by the unsafe handling of compressed HTTP request bodies, specifically zip bombs.

4

Which versions of cpp-httplib are affected by CVE-2026-22776?

CVE-2026-22776 affects all versions of cpp-httplib prior to 0.30.1.

5

What impact does CVE-2026-22776 have on applications?

CVE-2026-22776 can lead to a Denial of Service (DoS), potentially causing applications to become unresponsive.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203