Input validation error in libevent - #VU136947

 

Input validation error in libevent - #VU136947

Published: July 6, 2026


Vulnerability identifier: #VU136947
CSH Severity: Medium
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to smuggle HTTP requests and bypass access controls.

The vulnerability exists due to improper input validation in the evhttp HTTP parser when processing requests with multi-valued Transfer-Encoding headers. A remote attacker can send a specially crafted request with a comma-separated Transfer-Encoding value to smuggle HTTP requests and bypass access controls.

Exploitation requires the service to be deployed behind an intermediary that recognizes chunked as the final transfer coding and reuses the connection.


Affected software

libevent

Remediation

Install security update from vendor's website.

libevent - addressed in versions 2.1.13, 7.0

External References

Related Security Bulletins