critical
Security update for cpp-httplib
SUSE-SLES-16.0-150
This update for cpp-httplib fixes the following issues: - CVE-2025-66570: IP spoofing, log poisoning, and authorization bypass via header shadowing due to acceptance and parsing of client-controlled injected HTTP headers in incoming requests (bsc#1254734). - CVE-2025-66577: access and error log poisoning with spoofed client IPs due to unconditional acceptance of client-controlled `X-Forwarded-For` and `X-Real-IP` headers (bsc#1254735).
-
Release DateJan 15 2026
-
References
-
Typesecurity
-
Severitycritical
cloud_download Downloads
To download packages, you need to log in and have a valid subscription.
SUSE Linux Enterprise Server for SAP applications 16.0 ppc64le
-
Packages
SUSE Linux Enterprise Server for SAP applications 16.0 x86_64
-
Packages
SUSE Linux Enterprise Server 16.0 x86_64
-
Packages
SUSE Linux Enterprise Server 16.0 s390x
-
Packages
SUSE Linux Enterprise Server 16.0 ppc64le
-
Packages
SUSE Linux Enterprise Server 16.0 aarch64
-
Packages