SUSE alert openSUSE-SU-2026:0174-1 (cpp-httplib)
| From: | maintenance@opensuse.org | |
| To: | security-announce@lists.opensuse.org | |
| Subject: | openSUSE-SU-2026:0174-1: important: Security update for cpp-httplib | |
| Date: | Fri, 22 May 2026 00:04:44 +0200 | |
| Message-ID: | <20260521220444.8DEFAFCE7@maintenance.suse.de> | |
| Archive-link: | Article |
openSUSE Security Update: Security update for cpp-httplib ______________________________________________________________________________ Announcement ID: openSUSE-SU-2026:0174-1 Rating: important References: #1255835 #1256518 #1259220 #1259221 #1259373 Cross-References: CVE-2026-21428 CVE-2026-22776 CVE-2026-28434 CVE-2026-28435 CVE-2026-29076 CVSS scores: CVE-2026-21428 (SUSE): 8.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N CVE-2026-22776 (SUSE): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVE-2026-28434 (SUSE): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N CVE-2026-28435 (SUSE): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVE-2026-29076 (SUSE): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Affected Products: openSUSE Backports SLE-15-SP7 ______________________________________________________________________________ An update that fixes 5 vulnerabilities is now available. Description: This update for cpp-httplib fixes the following issues: - CVE-2026-21428: Fixed a server-side request forgery via header injection (boo#1255835) - CVE-2026-22776: Fixed unsafe handling of compressed HTTP request that could cause a denial of service (boo#1256518) - CVE-2026-28434: Fixed that the default exception handler could leak e.what() to clients via EXCEPTION_WHAT response header (boo#1259221) - CVE-2026-28435: Fixed a payload size limit bypass via gzip decompression in ContentReader (streaming) that could lead to denial of service (boo#1259220) - CVE-2026-29076: Fixed denial of service via crafted HTTP POST request (boo#1259373) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP7: zypper in -t patch openSUSE-2026-174=1 Package List: - openSUSE Backports SLE-15-SP7 (aarch64 i586 ppc64le s390x x86_64): cpp-httplib-devel-0.20.1-bp157.2.6.1 libcpp-httplib0_20-0.20.1-bp157.2.6.1 References: https://www.suse.com/security/cve/CVE-2026-21428.html https://www.suse.com/security/cve/CVE-2026-22776.html https://www.suse.com/security/cve/CVE-2026-28434.html https://www.suse.com/security/cve/CVE-2026-28435.html https://www.suse.com/security/cve/CVE-2026-29076.html https://bugzilla.suse.com/1255835 https://bugzilla.suse.com/1256518 https://bugzilla.suse.com/1259220 https://bugzilla.suse.com/1259221 https://bugzilla.suse.com/1259373
