VulnSea

libevent has 6 CVEs on record. Disclosure cadence is accelerating: 6 in the last 90 days against 0 in the 90 before. The busiest recent month was August 2026 with 6. The median CVSS is 8.0 (high), with 1 rated critical. None have a confirmed exploitation report.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
8.0
Publish → KEV
Last 90 days
6 prev 0

Products

  • libevent 6
6
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

libevent vulnerabilities

CVEs affecting libevent, newest first. Open any entry for full detail, references, and exploit status.

6 CVEsRSS

CVE-2026-63382Critical· 9.2PoC
1mo ago

Libevent is an event notification library

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, the libevent evhttp parser in http.c inconsistently handles duplicate Transfer-Encoding headers, comma-separated Transfer-Encoding values, and bare line feeds in…

Abyssallibevent · libeventEPSS 0.59%via NVD
CVE-2026-63383High· 8.7PoC
1mo ago

Libevent is an event notification library

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent can read beyond a contiguous evbuffer region in event_tagging.c when decode_tag_internal requests at most five bytes from evbuffer_pullup but iterates u…

Midnightlibevent · libeventEPSS 0.38%via NVD
CVE-2026-63495High· 7.5PoC
1mo ago

Libevent is an event notification library

Libevent is an event notification library. From 2.2.0-alpha-dev until 2.2.2-alpha, the libevent WebSocket server in ws.c accumulates fragmented frames in evws->incomplete_frames without enforcing a total message-size limit. An unauthenti…

Midnightlibevent · libeventEPSS 0.52%via NVD
CVE-2026-63388High· 8.4
1mo ago

Libevent is an event notification library

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a heap out-of-bounds write in bufferevent_sock.c when bufferevent_socket_set_conn_address_ copies a kernel-supplied AF_UNIX peer address into buffer…

Twilightlibevent · libeventEPSS 0.14%via NVD
CVE-2026-63387High· 7.0PoC
1mo ago

Libevent is an event notification library

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an off-by-one stack buffer overflow in evdns.c when dnsname_to_labels formats a name-bearing DNS record at the end of the 64 KB stack buffer allocat…

Midnightlibevent · libeventEPSS 0.42%via NVD
CVE-2026-63379Medium· 6.3
1mo ago

Libevent is an event notification library

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent processes chunked HTTP trailers in http.c through evhttp_read_trailer and merges them into request headers. The fix introduces evhttp_parse_headers_impl…

Sunlitlibevent · libeventEPSS 0.52%via NVD
libevent vulnerabilities (CVEs) · VulnSea