CVE-2026-63495
Libevent is an event notification library. From 2.2.0-alpha-dev until 2.2.2-alpha, the libevent WebSocket server in ws.c accumulates fragmented frames in evws->incomplete_frames without enforcing a total message-size limit. An unauthenticated remote client can repeatedly send fragmented WebSocket frames below WS_MAX_RECV_FRAME_SZ with FIN=0, causing the evbuffer to grow without bound until the process or host exhausts memory. This issue is fixed in version 2.2.2-alpha.
- Published Aug 20, 2026
- CVSS 7.5 high
- 0.6% chance of exploitation in the next 30 days (EPSS)
- A fix is available
Affected software
In the news
- Multiple vulnerabilities in IBM products CERT-FR ·