Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has two HTTP parsing weaknesses in http.c. evhttp_decode_uri_internal decodes percent-encoded %00 bytes into literal NUL characters, which can cause downstream C string operations to truncate a path and bypass validation performed on a different representation. evhttp_header_is_valid_value also accepts obsolete line folding in header values containing carriage return or line feed characters, allowing a proxy and libevent to interpret headers differently and enabling header injection or access control bypass. The CRLF header acceptance is fixed in versions 2.1.13 and 2.2.2-alpha, but the reviewed patches do not clearly remediate the URI NUL-truncation condition.
CVSS Details
- CVSS 4.0 Base Score: 9.2 (CRITICAL)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libevent | Sep 21, 2026 | Aug 20, 2026 |
| Redhat_linux | — | Upgrade libevent-develUpgrade libevent-debugsourceUpgrade libevent-docUpgrade libevent-debuginfoNo solution existsUpgrade libevent | Sep 7, 2026 | Aug 20, 2026 |
| Rocky_linux | — | Upgrade libevent-debuginfoUpgrade libevent-develUpgrade libevent-debugsourceUpgrade libevent | Sep 18, 2026 | Sep 17, 2026 |
| Ubuntu | — | Upgrade libevent-2.1-7t64Upgrade libevent-extra-2.1-7Upgrade libevent-core-2.1-7t64Upgrade libevent-devUpgrade libevent-core-2.1-7Upgrade libevent-extra-2.1-7 (Ubuntu Pro)Upgrade libevent-2.0-5 (Ubuntu Pro)Upgrade libevent-2.1-7 (Ubuntu Pro)Upgrade libevent-2.1-6 (Ubuntu Pro)Upgrade libevent-extra-2.1-7t64Upgrade libevent-extra-2.1-6 (Ubuntu Pro)Upgrade libevent-extra-2.0-5 (Ubuntu Pro)Upgrade libevent-core-2.1-6 (Ubuntu Pro)Upgrade libevent-2.1-7Upgrade libevent-dev (Ubuntu Pro)Upgrade libevent-core-2.1-7 (Ubuntu Pro)Upgrade libevent-core-2.0-5 (Ubuntu Pro) | Sep 2, 2026 | Sep 1, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub