PT-2026-76583 · Libevent+2 · Libevent+2
CVE-2026-63385
·
Published
2026-07-01
·
Updated
2026-09-01
CVSS v2.0
9.7
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:P |
Name of the Vulnerable Software and Affected Versions
Libevent versions prior to 2.1.13
Libevent versions prior to 2.2.2-alpha
Description
Two HTTP parsing weaknesses exist in the
http.c file. The function evhttp decode uri internal() decodes percent-encoded %00 bytes into literal NUL characters, which may lead to path truncation during downstream C string operations and allow validation bypass. Additionally, the function evhttp header is valid value() accepts obsolete line folding in header values containing carriage return or line feed characters. This discrepancy in how a proxy and the library interpret headers can enable header injection or access control bypass.Recommendations
Update to version 2.1.13 or later.
Update to version 2.2.2-alpha or later.
Exploit
Fix
HTTP Request/Response Smuggling
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Libevent
Linuxmint
Ubuntu