PT-2026-76583 · Libevent+2 · Libevent+2

CVE-2026-63385

·

Published

2026-07-01

·

Updated

2026-09-01

CVSS v2.0

9.7

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:P
Name of the Vulnerable Software and Affected Versions Libevent versions prior to 2.1.13 Libevent versions prior to 2.2.2-alpha
Description Two HTTP parsing weaknesses exist in the http.c file. The function evhttp decode uri internal() decodes percent-encoded %00 bytes into literal NUL characters, which may lead to path truncation during downstream C string operations and allow validation bypass. Additionally, the function evhttp header is valid value() accepts obsolete line folding in header values containing carriage return or line feed characters. This discrepancy in how a proxy and the library interpret headers can enable header injection or access control bypass.
Recommendations Update to version 2.1.13 or later. Update to version 2.2.2-alpha or later.

Exploit

Fix

HTTP Request/Response Smuggling

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-96897
AZL-96947
AZL-97539
AZL-97566
BDU:2026-12662
CVE-2026-63385
ECHO-7FFD-12B3-6870
GHSA-JCWH-PVF2-73P2
OESA-2026-3268
USN-8710-1

Affected Products

Libevent
Linuxmint
Ubuntu