libevent

10 known vulnerabilities in libevent, 2 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-63495 CVSS 7.5 high Libevent is an event notification library. From 2.2.0-alpha-dev until 2.2.2-alpha, the libevent WebSocket server in ws.c accumulates…
  • CVE-2026-63388 CVSS 8.4 high Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a heap out-of-bounds write in bufferevent_sock.c…
  • CVE-2026-63387 CVSS 7.0 high Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an off-by-one stack buffer overflow in evdns.c…
  • CVE-2026-63385 CVSS 9.2 critical Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has two HTTP parsing weaknesses in http.c…
  • CVE-2026-63384 CVSS 8.7 high Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an incorrect integer conversion in…
  • CVE-2026-63383 CVSS 8.7 high Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent can read beyond a contiguous evbuffer region in…
  • CVE-2026-63382 CVSS 9.2 critical Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, the libevent evhttp parser in http.c inconsistently handles…
  • CVE-2026-63381 CVSS 5.8 medium Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a use-after-free in buffer.c when…
  • CVE-2026-63380 CVSS 5.7 medium Libevent is an event notification library. Prior to 2.2.2-alpha, libevent can dereference invalid list pointers in ws.c when…
  • CVE-2026-63379 CVSS 6.3 medium Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent processes chunked HTTP trailers in http.c through…