CVE-2026-31870
Last modified
CVE-2026-31870 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.37.1, when a cpp-httplib client uses the streaming API (httplib::stream::Get, httplib::stream::Post, etc.), the library calls std::stoull() directly on the Content-Length header value received from the server with no input validation and no exception handling. EPSS estimates a 0.45% chance of exploitation in the next 30 days.
Description
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.37.1, when a cpp-httplib client uses the streaming API (httplib::stream::Get, httplib::stream::Post, etc.), the library calls std::stoull() directly on the Content-Length header value received from the server with no input validation and no exception handling. std::stoull throws std::invalid_argument for non-numeric strings and std::out_of_range for values exceeding ULLONG_MAX. Since nothing catches these exceptions, the C++ runtime calls std::terminate(), which kills the process with SIGABRT. Any server the client connects to — including servers reached via HTTP redirects, third-party APIs, or man-in-the-middle positions can crash the client application with a single HTTP response. No authentication is required. No interaction from the end user is required. The crash is deterministic and immediate. This vulnerability is fixed in 0.37.1.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Yhirose | Cpp-Httplib | < 0.37.1 |
References
- https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-39q5-hh6x-jpxxExploit, Mitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-31870?
How severe is CVE-2026-31870?
How do I fix CVE-2026-31870?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-31865Elysia is a Typescript framework for request validation, typ…5.3
- CVE-2026-31866flagd is a feature flag daemon with a Unix philosophy. Prior…7.5
- CVE-2026-31867Craft Commerce is an ecommerce platform for Craft CMS. Prior…4.8
- CVE-2026-31868Parse Server is an open source backend that can be deployed …6.1
- CVE-2026-31869Discourse is an open-source discussion platform. Prior to ve…4.3
- CVE-2026-3187A vulnerability was identified in feiyuchuixue sz-boot-paren…9.8
- CVE-2026-31871Parse Server is an open source backend that can be deployed …9.8
- CVE-2026-31872Parse Server is an open source backend that can be deployed …7.5
- CVE-2026-31873Unhead is a document head and template manager. Prior to 2.1…6.1
- CVE-2026-31874Taskosaur is an open source project management platform with…9.8
- CVE-2026-31875Parse Server is an open source backend that can be deployed …5.9
- CVE-2026-31876Notesnook is a note-taking app focused on user privacy & eas…5.4
Are you affected by CVE-2026-31870?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
