Executive brief
cpp-httplib is a widely used C++ library for adding web server and client functionality to applications. A security flaw in how the library handles encrypted (HTTPS) connections to specific IP addresses allows attackers to bypass security certificate checks. This could enable a "man-in-the-middle" attack where an unauthorized party intercepts, reads, or modifies sensitive data transmitted between the application and the server.
Technical details
A certificate validation bypass exists in cpp-httplib when using Mbed TLS (v0.31.0-0.46.1) or wolfSSL (v0.33.0-0.46.1) backends. When a client connects to an IP-literal host (e.g., https://1.1.1.1/) with certificate verification enabled, the library incorrectly downgrades or skips certificate chain validation. Specifically, SSLClient only performs a post-handshake IP SAN match without verifying the trust chain, and WebSocketClient on Mbed TLS may skip verification entirely. An attacker capable of intercepting network traffic can present a self-signed or untrusted certificate with a matching IP SAN to decrypt or alter communications. This issue is resolved in version 0.47.0 by ensuring chain verification remains active for IP hosts and performing identity checks post-handshake.
Affected products
- yhirose cpp-httplib 0.31.0 - 0.46.1
Timeline
- 2026-06-10: patched: Version 0.47.0 released
- 2026-06-16: advisory: GitHub Security Advisory published
- 2026-07-10: disclosed: CVE-2026-54919 published to NVD