Libevent 是一个事件通知库。在 2.1.13 之前以及 2.2.2-alpha 版本中,libevent 在 中存在两个 HTTP 解析方面的安全弱点。 第一个弱点涉及函数 ,它会将经过百分号编码的 字节解码为字面意义上的 NUL(零)字符。这可能导致下游的 C 字符串操作提前截断路径,从而绕过在其他表示形式上执行的安全验证。 第二个弱点涉及函数 ,该函数接受过时的标头值折行(line folding)行为,即允许标头值中包含回车符(CR)或换行符(LF)。这使得代理服务器和 libevent 可能对同一标
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-63382 | 9.2 CRITICAL | libevent evhttp: Multiple HTTP Parser Bugs Enable Request Smuggling |
| CVE-2026-63384 | 8.7 HIGH | Libevent: `evtag_unmarshal_header()` decodes a wire `uint32` length into a signed `int` re |
| CVE-2026-63383 | 8.7 HIGH | Libevent: decode_tag_internal() can lead to out-of-bounds read |
| CVE-2026-63388 | 8.4 HIGH | Libevent: Heap out-of-bounds write in bufferevent_socket_set_conn_address_ reachable via A |
| CVE-2026-63495 | 7.5 HIGH | Libevent: Unbounded memory accumulation in WebSocket server via fragmented frames |
| CVE-2026-63387 | 7.0 HIGH | Libevent: Off-by-one stack buffer overflow in dnsname_to_labels via crafted DNS server res |
| CVE-2026-63379 | 6.3 MEDIUM | Libevent: HTTP Header smuggling |
| CVE-2026-63381 | 5.8 MEDIUM | Libevent: Dangling Pointer in `evbuffer_add_buffer_reference` |
| CVE-2026-63380 | 5.7 MEDIUM | Libevent: Null Pointer Dereference in `evws_new_session` |
No comments yet