---
title: "CVE-2025-52887\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2025-52887?format=md
keywords: index, follow
---

# CVE-2025-52887

Publication date 26 June 2025

Last updated 23 February 2026

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**7.5 · High**

[Score breakdown](https://ubuntu.com/security/CVE-2025-52887?format=md#impact-score)

Toggle side navigation

## Description

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS
library. In version 0.21.0, when many http headers fields are passed in,
the library does not limit the number of headers, and the memory associated
with the headers will not be released when the connection is disconnected.
This leads to potential exhaustion of system memory and results in a server
crash or unresponsiveness. Version 0.22.0 contains a patch for the issue.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| cpp-httplib | 26.04 LTS resolute | Vulnerable |
| 25.10 questing | Ignored end of life, was needed |
| 25.04 plucky | Ignored end of life, was needs-triage |
| 24.10 oracular | Ignored end of life, was needs-triage |
| 24.04 LTS noble | Vulnerable |
| 22.04 LTS jammy | Vulnerable |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2025-52887?format=md#patch-details)

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| cpp-httplib | * Upstream:   [28dcf37](https://github.com/yhirose/cpp-httplib/commit/28dcf379e82a2cdb544d812696a7fd46067eb7f9) |

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

7.5 · High

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Privileges required | None |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | None |
  | Integrity impact | None |
  | Availability impact | High |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 7.5 · High |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-52887)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2025-52887)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2025-52887)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2025-52887)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2025-52887>
* <https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-xjhg-gf59-p92h>
* <https://github.com/yhirose/cpp-httplib/commit/28dcf379e82a2cdb544d812696a7fd46067eb7f9 (v0.22.0)>
* <https://github.com/yhirose/cpp-httplib/commit/28dcf379e82a2cdb544d812696a7fd46067eb7f9>
