Libevent Event Notification Library Vulnerability in HTTP Parser
CVE-2026-63382
9.2CRITICAL
What is CVE-2026-63382?
The evhttp parser in Libevent prior to versions 2.1.13 and 2.2.2-alpha is vulnerable to improper handling of duplicate Transfer-Encoding headers and other inconsistencies. An attacker could exploit these vulnerabilities through crafted HTTP requests that desynchronize request boundaries, allowing unauthorized access or potentially compromising cache integrity. The flawed parsing also fails to properly recognize valid Transfer-Encoding headers in certain situations, which could lead to malicious request injection behind proxies.
Affected Version(s)
libevent >= 2.2.0-alpha, < 2.2.2-alpha < 2.2.0-alpha, 2.2.2-alpha
libevent < 2.1.13 < 2.1.13
