Use-after-free in Cpp-httplib - CVE-2026-77358
Published: August 25, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service and potentially execute arbitrary code.
The vulnerability exists due to use-after-free in WebSocketClient::shutdown_and_close() when closing a TLS WebSocket connection. A local user can trigger teardown of a crafted wss:// session to cause a denial of service and potentially execute arbitrary code.
The issue is reachable through the public WebSocketClient API and requires SSL support with an open TLS WebSocket connection at teardown or reconnect.
Affected software
openEuler
cpp-httplib
cpp-httplib-debuginfo
cpp-httplib-debugsource
cpp-httplib-devel
How to mitigate CVE-2026-77358
cpp-httplib - update to 0.46.0-2
cpp-httplib-debuginfo - update to 0.46.0-2
cpp-httplib-debugsource - update to 0.46.0-2
cpp-httplib-devel - update to 0.46.0-2