Junglewise Threat Intelligence

CVE-2026-63385: Libevent HTTP parsing weaknesses in header validation and URI decoding

CVE-2026-63385 · Severity: info · Published 2026-08-20

Technologies: Libevent Project Libevent.

Executive brief

Libevent is a widely-used event notification library that handles network communication for many applications. Two HTTP parsing flaws allow attackers to bypass security checks: one permits NUL byte injection in URI paths causing string truncation, and another accepts obsolete header line folding that enables header injection. These weaknesses could allow an attacker to access restricted resources, inject malicious headers, or bypass access controls on systems using affected versions.

Technical details

Libevent contains two distinct HTTP parsing vulnerabilities in http.c. The first flaw exists in evhttp_decode_uri_internal, which decodes percent-encoded %00 bytes into literal NUL characters; when these NUL bytes are processed by downstream C string operations, they cause path truncation, allowing an attacker to bypass URI validation checks that operate on a different representation. The second vulnerability occurs in evhttp_header_is_valid_value, which incorrectly accepts obsolete RFC 5322 line folding (carriage return and line feed characters within header values). This permits header injection attacks that can cause proxy chains and libevent to interpret headers differently, potentially enabling access control bypass. The CRLF header issue is fixed in versions 2.1.13 and 2.2.2-alpha, but the NUL-truncation condition in URI decoding remains inadequately addressed in the reviewed patches. Both issues are network-reachable and require no authentication or user interaction.

Affected products

  • Libevent Project Libevent prior to 2.1.13 and 2.2.2-alpha

Timeline

  • 2026-08-20: disclosed

References