libevent 是一个事件通知库。在 2.1.13 及 2.2.2-alpha 之前的版本中,libevent 通过 函数处理 中的 HTTP 分块传输编码(chunked)响应尾部(trailers),并将这些尾部字段合并到请求头(request headers)中。修复方案引入了 函数以及一个临时的尾部头字段列表。未授权的远程攻击者可在尾部字段中嵌入安全敏感字段,从而导致上游代理服务器与 libevent 应用对有效头字段产生不同解释,进而引发请求走私(header smuggling)、授权绕过、代理头伪造
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-63382 | 9.2 CRITICAL | libevent evhttp: Multiple HTTP Parser Bugs Enable Request Smuggling |
| CVE-2026-63385 | 9.2 CRITICAL | Libevent: HTTP header handling bugs create risk of access control bypass. |
| CVE-2026-63384 | 8.7 HIGH | Libevent: `evtag_unmarshal_header()` decodes a wire `uint32` length into a signed `int` re |
| CVE-2026-63383 | 8.7 HIGH | Libevent: decode_tag_internal() can lead to out-of-bounds read |
| CVE-2026-63388 | 8.4 HIGH | Libevent: Heap out-of-bounds write in bufferevent_socket_set_conn_address_ reachable via A |
| CVE-2026-63495 | 7.5 HIGH | Libevent: Unbounded memory accumulation in WebSocket server via fragmented frames |
| CVE-2026-63387 | 7.0 HIGH | Libevent: Off-by-one stack buffer overflow in dnsname_to_labels via crafted DNS server res |
| CVE-2026-63381 | 5.8 MEDIUM | Libevent: Dangling Pointer in `evbuffer_add_buffer_reference` |
| CVE-2026-63380 | 5.7 MEDIUM | Libevent: Null Pointer Dereference in `evws_new_session` |
No comments yet