A critical vulnerability, tracked as CVE-2025-66570, has been discovered in cpp-httplib, a widely used single-header C++ HTTP/HTTPS library. The flaw allows attackers to supply reserved HTTP header names such as REMOTE_ADDR, REMOTE_PORT, LOCAL_ADDR, and LOCAL_PORT in client requests, which are then incorrectly processed by affected versions of the library (≤ 0.26.0). This enables malicious actors to override server-side connection metadata, potentially misleading application logic that depends on these fields for authorization, logging, or network trust decisions.
The vulnerability is particularly severe because cpp-httplib is often embedded transitively in various projects, sometimes without developers' awareness. The issue has been addressed in version 0.27.0, and users are advised to search their codebases for direct or vendored copies of httplib.h to determine exposure. Applications that rely on the affected header values for security-sensitive operations are at heightened risk and should update to the patched version immediately.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Public references describing CVE-2025-66570 and its impact on cpp-httplib were published, highlighting risks to authorization, logging, and trust decisions in affected applications. The disclosure also noted the library's broad use, including transitive inclusion in other projects.
The issue was fixed in cpp-httplib version 0.27.0 by preventing clients from supplying reserved internal header names. Guidance accompanying the fix advised users to upgrade and avoid relying on get_header_value() for sensitive metadata decisions.
A critical vulnerability, CVE-2025-66570, was identified in cpp-httplib versions 0.26.0 and earlier. The flaw allows client-supplied reserved headers such as REMOTE_ADDR and LOCAL_PORT to override server-injected metadata, enabling spoofing of connection details.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.