PT-2026-76580 · Libevent+2 · Libevent+2

CVE-2026-63382

·

Published

2026-07-01

·

Updated

2026-09-01

CVSS v4.0

9.7

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Libevent versions prior to 2.1.13 Libevent versions prior to 2.2.2-alpha
Description The evhttp parser in http.c inconsistently handles duplicate Transfer-Encoding headers, comma-separated Transfer-Encoding values, and bare line feeds in chunked framing. Specifically, the evhttp find header() function may select only the first header, and the evhttp handle chunked read() function uses EVBUFFER EOL CRLF instead of EVBUFFER EOL CRLF STRICT, which allows the acceptance of bare LF chunk terminators. When deployed behind a proxy that frames requests differently, an unauthenticated remote attacker can desynchronize request boundaries to smuggle a second request, which may lead to cache poisoning or the bypassing of access controls.
Recommendations Update to version 2.1.13. Update to version 2.2.2-alpha.

Exploit

Fix

HTTP Request/Response Smuggling

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-96900
AZL-96944
AZL-97536
AZL-97560
BDU:2026-12659
CVE-2026-63382
ECHO-EA71-BE9C-766F
GHSA-Q39V-W2G7-GR8J
OESA-2026-3268
USN-8710-1

Affected Products

Libevent
Linuxmint
Ubuntu