Ubuntu alert USN-7962-1 (cpp-httplib)
| From: | noreply+usn-bot@canonical.com | |
| To: | ubuntu-security-announce@lists.ubuntu.com | |
| Subject: | [USN-7962-1] cpp-httplib vulnerability | |
| Date: | Thu, 15 Jan 2026 14:36:56 +0000 | |
| Message-ID: | <E1vgOT3-0002E2-01@lists.ubuntu.com> |
========================================================================== Ubuntu Security Notice USN-7962-1 January 14, 2026 cpp-httplib vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 - Ubuntu 25.04 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: cpp-httplib could allow unintended access to network services if it received specially crafted network traffic. Software Description: - cpp-httplib: A C++11 single-file header-only cross platform HTTP/HTTPS library. Details: It was discovered that cpp-httplib did not correctly handle HTTP headers. A remote attacker could possibly use this issue to bypass authorization and impersonate users. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 libcpp-httplib-dev 0.18.7-1ubuntu0.25.10.1 libcpp-httplib0.18 0.18.7-1ubuntu0.25.10.1 Ubuntu 25.04 libcpp-httplib-dev 0.18.7-1ubuntu0.25.04.1 libcpp-httplib0.18 0.18.7-1ubuntu0.25.04.1 Ubuntu 24.04 LTS libcpp-httplib-dev 0.14.3+ds-1.1ubuntu0.1~esm1 Available with Ubuntu Pro libcpp-httplib0.14t64 0.14.3+ds-1.1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 22.04 LTS libcpp-httplib-dev 0.10.3+ds-1ubuntu0.1~esm1 Available with Ubuntu Pro libcpp-httplib0 0.10.3+ds-1ubuntu0.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7962-1 CVE-2025-66570 Package Information: https://launchpad.net/ubuntu/+source/cpp-httplib/0.18.7-1... https://launchpad.net/ubuntu/+source/cpp-httplib/0.18.7-1...
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmlo+wwACgkQcpJm3tlz hgGhdw//bHCpSBGkrCJS42xBsAPa+5F+YJdYz7jEEvHKrqcgz+yjd0WXgKMoqD0h 7iTysqMLe9hnrvDR3b2A+j6zJAyrAdnMYL7EcTJD7igpphj7+VmUiskkyiRsLYi1 QNVx3b9v/PV45TWfnO6hNVOUqU+nWfrXuM4OvChk16G1s8/gzJObHpQodMxxRvwp dwCPJ63FsBqUF/d6Lwg63r/ABnpEAveunBI8/vG7CdUYKkAPOxjdfypVTRNAlvXa HRBC/gzwBzmkRzREamYHUzKMB8HHMztNe7EYWQQUYYZTZqEIG9rbVkaSR3P4qkX1 eE3YB26505P8Ni0Fhij61111CO8thF0cVSytFfY5FzqOASheEFCCXEDJ5dEGqOLF wfLnSprW8dDmzjeg7GIdttgoMFbDQWol5hVqNqVxU+W6VNtFhvx0wu9lXV1DyziL YJto4gRAZ3iejUmlGUgI5dQwWFUOVKMUEFTvrAvu/NcqpfB8tIbW3hmoTneSYm9U GdEfora12nGLoXADSaRUHjl3mKYkX2rJvueZTcGYqBEo0Dd4O9azzukl0LeR3yRb bRbxsZCdA/SDONgJZNt1zlKbjh4DJ5I00pw7osefM+kXKJeDHsMlvmihAhgp6eq+ OMcJZG5uS59aPsuahkudnwhuap23lZkOT1Wg9DdzDiDpkkppFwM= =vFzA -----END PGP SIGNATURE-----
