cpp-httplib through 0.5.8 does not filter \r\n in parameters passed into the setredirect and setheader functions, which creates possibilities for CRLF injection and HTTP response splitting in some specific contexts.
{ "versions": [ { "introduced": "0" }, { "last_affected": "0.5.8" } ] }
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-11709.json"