Libevent 是一个事件通知库。在版本 2.1.13 和 2.2.2-alpha 之前,libevent 在 event_tagging.c 中存在一个不正确的整数转换漏洞。当 evtag_unmarshal_header 调用 evtag_decode_int 来解码攻击者控制的 uint32 类型负载长度,并将其作为 signed int 返回时,会出现问题。当值超过 INT_MAX 时,结果会变成负数或被截断。随后,evtag_unmarshal_string 可能会在分配内存大小计算中使用该转换后的值,
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-63382 | 9.2 CRITICAL | libevent evhttp: Multiple HTTP Parser Bugs Enable Request Smuggling |
| CVE-2026-63385 | 9.2 CRITICAL | Libevent: HTTP header handling bugs create risk of access control bypass. |
| CVE-2026-63383 | 8.7 HIGH | Libevent: decode_tag_internal() can lead to out-of-bounds read |
| CVE-2026-63388 | 8.4 HIGH | Libevent: Heap out-of-bounds write in bufferevent_socket_set_conn_address_ reachable via A |
| CVE-2026-63495 | 7.5 HIGH | Libevent: Unbounded memory accumulation in WebSocket server via fragmented frames |
| CVE-2026-63387 | 7.0 HIGH | Libevent: Off-by-one stack buffer overflow in dnsname_to_labels via crafted DNS server res |
| CVE-2026-63379 | 6.3 MEDIUM | Libevent: HTTP Header smuggling |
| CVE-2026-63381 | 5.8 MEDIUM | Libevent: Dangling Pointer in `evbuffer_add_buffer_reference` |
| CVE-2026-63380 | 5.7 MEDIUM | Libevent: Null Pointer Dereference in `evws_new_session` |
No comments yet