Echo: cpp-httplib: security update to 0.18.7-1+e1

high Tenable Self-Hosted Container Security Plugin ID 463733

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- cpp-httplib is a C++ header-only HTTP/HTTPS server and client library. Prior to version 0.20.1, the
library fails to enforce configured size limits on incoming request bodies when `Transfer-Encoding:
chunked` is used or when no `Content-Length` header is provided. A remote attacker can send a chunked
request without the terminating zero-length chunk, causing uncontrolled memory allocation on the server.
This leads to potential exhaustion of system memory and results in a server crash or unresponsiveness.
Version 0.20.1 fixes the issue by enforcing limits during parsing. If the limit is exceeded at any point
during reading, the connection is terminated immediately. A short-term workaround through a Reverse Proxy
is available. If updating the library immediately is not feasible, deploy a reverse proxy (e.g., Nginx,
HAProxy) in front of the `cpp-httplib` application. Configure the proxy to enforce maximum request body
size limits, thereby stopping excessively large requests before they reach the vulnerable library code.
(CVE-2025-46728)

Solution

Update the cpp-httplib library and its related packages to version 0.18.7-1+e1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2025-46728

Plugin Details

Severity: High

ID: 463733

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.67

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.1

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2025-46728

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 1/28/2026

Vulnerability Publication Date: 5/6/2025

Reference Information

CVE: CVE-2025-46728