PT-2026-76580 · Libevent+2 · Libevent+2
CVE-2026-63382
·
Published
2026-07-01
·
Updated
2026-09-01
CVSS v4.0
9.7
Critical
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Libevent versions prior to 2.1.13
Libevent versions prior to 2.2.2-alpha
Description
The evhttp parser in http.c inconsistently handles duplicate Transfer-Encoding headers, comma-separated Transfer-Encoding values, and bare line feeds in chunked framing. Specifically, the
evhttp find header() function may select only the first header, and the evhttp handle chunked read() function uses EVBUFFER EOL CRLF instead of EVBUFFER EOL CRLF STRICT, which allows the acceptance of bare LF chunk terminators. When deployed behind a proxy that frames requests differently, an unauthenticated remote attacker can desynchronize request boundaries to smuggle a second request, which may lead to cache poisoning or the bypassing of access controls.Recommendations
Update to version 2.1.13.
Update to version 2.2.2-alpha.
Exploit
Fix
HTTP Request/Response Smuggling
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Libevent
Linuxmint
Ubuntu