Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-63382

libevent evhttp: Multiple HTTP Parser Bugs Enable Request Smuggling
Back to all
CVE

CVE-2026-63382

libevent evhttp: Multiple HTTP Parser Bugs Enable Request Smuggling

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, the libevent evhttp parser in http.c inconsistently handles duplicate Transfer-Encoding headers, comma-separated Transfer-Encoding values, and bare line feeds in chunked framing. evhttpfindheader can select only the first header, evhttpchecktransferencoding was absent so the previous whole-string comparison fails to recognize valid lists ending in chunked, and evhttphandlechunkedread uses EVBUFFEREOLCRLF rather than EVBUFFEREOLCRLFSTRICT, accepting bare LF chunk terminators. When libevent is deployed behind a proxy that frames the same request differently, an unauthenticated remote attacker can desynchronize request boundaries and smuggle a second request, potentially bypassing access controls or poisoning caches. This issue is fixed in versions 2.1.13 and 2.2.2-alpha.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.2
-
4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
C
H
U
0
-
C
H
U
-

Related Resources

No items found.

References

https://github.com/libevent/libevent/releases/tag/release-2.1.13-stable, https://github.com/libevent/libevent/releases/tag/release-2.2.2-alpha, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63382.json, https://github.com/libevent/libevent/security/advisories/GHSA-q39v-w2g7-gr8j, https://nvd.nist.gov/vuln/detail/CVE-2026-63382, https://github.com/libevent/libevent/commit/10abb34b8dc3e1184de315dd261ce4b77563cda6, https://github.com/libevent/libevent/commit/5119ceb00557bf007f9065709e852686f3c0bb6e, https://github.com/libevent/libevent/commit/83ba67373032334559b82409db035dd8c3cc1660, https://github.com/libevent/libevent/commit/ac38703b2d312200c4f967f02936af0118d384a0

Severity

0

CVSS Score
0
10

Basic Information

Base CVSS
0
EPSS Probability
0.00784%
EPSS Percentile
0.5427%
Introduced Version
0
Fix Available
ac38703b2d312200c4f967f02936af0118d384a0,0:2.1.8-11.el8_10,0:2.1.13-1.el9_8,2.1.13-1.el10_2,2.1.12-stable-8+deb12u1,2.1.13-stable-1~deb13u1,2.1.8-stable-4ubuntu0.1~esm1,2.1.11-stable-1ubuntu0.1~esm1,2.1.12-stable-9ubuntu2.1,2.1.12-stable-1ubuntu0.1,0:2.1.13-1.el10_2

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading