Insufficiently protected credentials in Cpp-httplib - CVE-2026-102944
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose session cookies.
The vulnerability exists due to improper protection of credentials in the cross-origin redirect handling of cpp-httplib when following cross-origin HTTP redirects. A remote attacker can cause a redirect to an attacker-controlled server to disclose session cookies.
Only HTTP 301, 302, 307, and 308 redirects are affected; HTTP 303 redirects clear all headers.