Vulnerabilidades en libevent
10 resultadosAnálisis Vexday
A libevent apresenta 10 vulnerabilidades catalogadas, todas publicadas nos últimos 90 dias, indicando risco recente e potencialmente ainda em fase de mitigação. Embora nenhuma esteja sob ataque ativo conhecido (KEV), apenas 2 atingem nível crítico, a predominância de CWE-444 (HTTP Request Smuggling) aponta fragilidade estrutural em validação de requisições que pode comprometer a segurança de aplicações dependentes. A concentração temporal das divulgações sugere descoberta sistemática de falhas na biblioteca.
CVE-2026-63382CRITICALlibevent evhttp: Multiple HTTP Parser Bugs Enable Request SmugglingEPSS 0.6%CVE-2026-63379MEDIUMLibevent: HTTP Header smugglingEPSS 0.5%CVE-2026-63495HIGHLibevent: Unbounded memory accumulation in WebSocket server via fragmented framesEPSS 0.5%CVE-2026-63387HIGHLibevent: Off-by-one stack buffer overflow in dnsname_to_labels via crafted DNS server responseEPSS 0.4%CVE-2026-63385CRITICALLibevent: HTTP header handling bugs create risk of access control bypass.EPSS 0.4%CVE-2026-63384HIGHLibevent: `evtag_unmarshal_header()` decodes a wire `uint32` length into a signed `int` return value.EPSS 0.4%CVE-2026-63383HIGHLibevent: decode_tag_internal() can lead to out-of-bounds readEPSS 0.4%CVE-2026-63388HIGHLibevent: Heap out-of-bounds write in bufferevent_socket_set_conn_address_ reachable via AF_UNIX acceptEPSS 0.1%CVE-2026-63381MEDIUMLibevent: Dangling Pointer in `evbuffer_add_buffer_reference`EPSS 0.1%CVE-2026-63380MEDIUMLibevent: Null Pointer Dereference in `evws_new_session`EPSS 0.1%