SB2026042454 - Fedora 42 update for cpp-httplib
Published: April 24, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper Certificate Validation (CVE-ID: CVE-2026-32627)
The vulnerability allows a remote attacker to intercept HTTPS connections and disclose sensitive information.
The vulnerability exists due to improper certificate validation in ClientImpl::create_redirect_client() in httplib.h when following an HTTPS redirect through a configured proxy. A remote attacker can return a crafted redirect response and present a forged or self-signed certificate to intercept HTTPS connections and disclose sensitive information.
Only builds with SSL support are affected, and exploitation requires the client to have a proxy configured with redirect following enabled.
Remediation
Install update from vendor's website.