CVE-2026-63383
Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent can read beyond a contiguous evbuffer region in event_tagging.c when decode_tag_internal requests at most five bytes from evbuffer_pullup but iterates using the full logical buffer length. A fragmented evbuffer containing a six-byte malformed tag can therefore advance past the pullup window and trigger an out-of-bounds read, which can crash a process that decodes attacker-controlled tagged RPC data. This issue is fixed in versions 2.1.13 and 2.2.2-alpha.
- Published Aug 20, 2026
- CVSS 8.7 high
- 0.5% chance of exploitation in the next 30 days (EPSS)
- A fix is available
Affected software
In the news
- Multiple vulnerabilities in VMware products CERT-FR ·
- Multiple vulnerabilities in IBM products CERT-FR ·