Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, the libevent evhttp parser in http.c inconsistently handles duplicate Transfer-Encoding headers, comma-separated Transfer-Encoding values, and bare line feeds in chunked framing. evhttp_find_header can select only the first header, evhttp_check_transfer_encoding_ was absent so the previous whole-string comparison fails to recognize valid lists ending in chunked, and evhttp_handle_chunked_read uses EVBUFFER_EOL_CRLF rather than EVBUFFER_EOL_CRLF_STRICT, accepting bare LF chunk terminators. When libevent is deployed behind a proxy that frames the same request differently, an unauthenticated remote attacker can desynchronize request boundaries and smuggle a second request, potentially bypassing access controls or poisoning caches. This issue is fixed in versions 2.1.13 and 2.2.2-alpha.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-444"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63382.json"
}{
"extracted_events": [
{
"introduced": "2.2.0-alpha"
},
{
"fixed": "2.2.2-alpha"
},
{
"introduced": "0"
},
{
"fixed": "2.1.13"
}
],
"source": [
"AFFECTED_FIELD",
"REFERENCES"
]
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63382.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "159443554126248192493229143747497657830",
"length": 554
},
"id": "CVE-2026-63382-09212634",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/libevent/libevent/commit/df3ecad3a040fd6d4fad4287defe113395de6fd7",
"target": {
"file": "test/regress_http.c",
"function": "http_check_transfer_encoding_test"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"232009363620329056628390670129698999396",
"301927956550500463733001079496948051892",
"302846894707599898881518362108152763491",
"210052224979536070281137964402414208542"
],
"threshold": 0.9
},
"id": "CVE-2026-63382-1a3ca03c",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/libevent/libevent/commit/5119ceb00557bf007f9065709e852686f3c0bb6e",
"target": {
"file": "http.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "29720660094429988911624257350654414811",
"length": 1396
},
"id": "CVE-2026-63382-266efb72",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/libevent/libevent/commit/ac38703b2d312200c4f967f02936af0118d384a0",
"target": {
"file": "http.c",
"function": "evhttp_read_header"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "54312597686892110452460201251458713018",
"length": 1628
},
"id": "CVE-2026-63382-5132a434",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/libevent/libevent/commit/10abb34b8dc3e1184de315dd261ce4b77563cda6",
"target": {
"file": "http.c",
"function": "evhttp_handle_chunked_read"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"292409626913952697780312546128864361636",
"48911316333907774450032958223250596426",
"267816818433322696405534976217335938577"
],
"threshold": 0.9
},
"id": "CVE-2026-63382-5d193cce",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/libevent/libevent/commit/ac38703b2d312200c4f967f02936af0118d384a0",
"target": {
"file": "http-internal.h"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "308400937445130025457393919580388502260",
"length": 1065
},
"id": "CVE-2026-63382-76f85aff",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/libevent/libevent/commit/83ba67373032334559b82409db035dd8c3cc1660",
"target": {
"file": "http.c",
"function": "evhttp_get_body"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"270762094980121927552802584929566056086",
"37564212311334647331345684303177453724",
"168570413533780985513641597969239978857"
],
"threshold": 0.9
},
"id": "CVE-2026-63382-923050c6",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/libevent/libevent/commit/df3ecad3a040fd6d4fad4287defe113395de6fd7",
"target": {
"file": "test/regress_http.c"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"270762094980121927552802584929566056086",
"37564212311334647331345684303177453724",
"168570413533780985513641597969239978857"
],
"threshold": 0.9
},
"id": "CVE-2026-63382-979e5bed",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/libevent/libevent/commit/79ddfb460847999b807cba76d04e73891f29c6ee",
"target": {
"file": "test/regress_http.c"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"292409626913952697780312546128864361636",
"48911316333907774450032958223250596426",
"267816818433322696405534976217335938577"
],
"threshold": 0.9
},
"id": "CVE-2026-63382-a376f433",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/libevent/libevent/commit/83ba67373032334559b82409db035dd8c3cc1660",
"target": {
"file": "http-internal.h"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "35224490696261019053090315553242569431",
"length": 1411
},
"id": "CVE-2026-63382-a735cfb1",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/libevent/libevent/commit/83ba67373032334559b82409db035dd8c3cc1660",
"target": {
"file": "http.c",
"function": "evhttp_read_header"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"232009363620329056628390670129698999396",
"301927956550500463733001079496948051892",
"302846894707599898881518362108152763491",
"193089320091580699121306918516168648171"
],
"threshold": 0.9
},
"id": "CVE-2026-63382-ae20f35d",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/libevent/libevent/commit/10abb34b8dc3e1184de315dd261ce4b77563cda6",
"target": {
"file": "http.c"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"99516876717233697971681569441425555600",
"321505742027719859756484394689243827805",
"166921988269945208330726582242303544451",
"272462270128366619676808891365251706672",
"101739781882283880791711184144758479571",
"32587973922429444777722015740822682536",
"229407517677749604417271354969663789061",
"90178132363687388181821893127025960286",
"22247395750450916610695992806932819396",
"151093420082438813915410561791252300143",
"267146152584600667737937962905459743732",
"244296681046564776749629984391425551630",
"299439234693367972321457905101427713020",
"48529953390494900503685318136989739977",
"147053079718748745807721029820436526951",
"79855943815832672741496733684339014390",
"72162232640439775493263860599031315867",
"121067529503147623449346205367829540766",
"135287174655085839407806908039695016964",
"106599715368436461889311398018389047609",
"39367626467257698307243720398820909675",
"118548499515817886124149454694486548706",
"88111539738133254015713355734017745107",
"255024896872254468840883927095505426013",
"114267716138868255645836626147837862319"
],
"threshold": 0.9
},
"id": "CVE-2026-63382-bce19751",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/libevent/libevent/commit/83ba67373032334559b82409db035dd8c3cc1660",
"target": {
"file": "http.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "33556705737908929032215014941627983842",
"length": 1057
},
"id": "CVE-2026-63382-c7f4b032",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/libevent/libevent/commit/ac38703b2d312200c4f967f02936af0118d384a0",
"target": {
"file": "http.c",
"function": "evhttp_get_body"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"117476648393786120008123475894810468187",
"196454199735878072416629015831504004669",
"252992453727377947888538980413417707756",
"13973253315252243435508545163209626635",
"325137767658559788418872616821116612150",
"274073271136253237971897300002481114705",
"56045080019540369849887529644493700705"
],
"threshold": 0.9
},
"id": "CVE-2026-63382-d881d6ac",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/libevent/libevent/commit/83ba67373032334559b82409db035dd8c3cc1660",
"target": {
"file": "test/regress_http.c"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"99516876717233697971681569441425555600",
"321505742027719859756484394689243827805",
"166921988269945208330726582242303544451",
"272462270128366619676808891365251706672",
"101739781882283880791711184144758479571",
"32587973922429444777722015740822682536",
"229407517677749604417271354969663789061",
"90178132363687388181821893127025960286",
"22247395750450916610695992806932819396",
"151093420082438813915410561791252300143",
"267146152584600667737937962905459743732",
"244296681046564776749629984391425551630",
"299439234693367972321457905101427713020",
"48529953390494900503685318136989739977",
"38829432815167987044553028529484704729",
"192148847848684925105003955526074786532",
"72162232640439775493263860599031315867",
"121067529503147623449346205367829540766",
"135287174655085839407806908039695016964",
"106599715368436461889311398018389047609",
"39367626467257698307243720398820909675",
"118548499515817886124149454694486548706",
"88111539738133254015713355734017745107",
"255024896872254468840883927095505426013",
"114267716138868255645836626147837862319"
],
"threshold": 0.9
},
"id": "CVE-2026-63382-da96cabc",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/libevent/libevent/commit/ac38703b2d312200c4f967f02936af0118d384a0",
"target": {
"file": "http.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "159443554126248192493229143747497657830",
"length": 554
},
"id": "CVE-2026-63382-ebc5ab94",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/libevent/libevent/commit/79ddfb460847999b807cba76d04e73891f29c6ee",
"target": {
"file": "test/regress_http.c",
"function": "http_check_transfer_encoding_test"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "279418785588684393413854686952928390591",
"length": 1865
},
"id": "CVE-2026-63382-f261d987",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/libevent/libevent/commit/5119ceb00557bf007f9065709e852686f3c0bb6e",
"target": {
"file": "http.c",
"function": "evhttp_handle_chunked_read"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"117476648393786120008123475894810468187",
"196454199735878072416629015831504004669",
"252992453727377947888538980413417707756",
"44495724699738943335942209210912962144",
"325137767658559788418872616821116612150",
"227726402891408782649622989353678379948",
"227215568266458251496186879841014266776"
],
"threshold": 0.9
},
"id": "CVE-2026-63382-fa17b9d2",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/libevent/libevent/commit/ac38703b2d312200c4f967f02936af0118d384a0",
"target": {
"file": "test/regress_http.c"
}
}
]
"2026-09-11T08:36:42Z"