Libevent Event Notification Library Vulnerability in HTTP Parser
CVE-2026-63382

9.2CRITICAL

Key Information:

Vendor

Libevent

Status
Vendor
CVE Published:
20 August 2026

What is CVE-2026-63382?

The evhttp parser in Libevent prior to versions 2.1.13 and 2.2.2-alpha is vulnerable to improper handling of duplicate Transfer-Encoding headers and other inconsistencies. An attacker could exploit these vulnerabilities through crafted HTTP requests that desynchronize request boundaries, allowing unauthorized access or potentially compromising cache integrity. The flawed parsing also fails to properly recognize valid Transfer-Encoding headers in certain situations, which could lead to malicious request injection behind proxies.

Affected Version(s)

libevent >= 2.2.0-alpha, < 2.2.2-alpha < 2.2.0-alpha, 2.2.2-alpha

libevent < 2.1.13 < 2.1.13

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.