Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2026-63385: libevent library allows remote code execution
CVE-2026-63385 · published 13 days ago
Summary
The libevent library used in several Linux distributions can be tricked into running malicious code. This could let an attacker take control of the affected system. Apply the latest updates for libevent from your Linux vendor as soon as possible.
What to do
- Update canonical libevent to version 2.0.21-stable-1ubuntu1.14.04.2+esm1.
- Update canonical libevent to version 2.0.21-stable-2ubuntu0.16.04.1+esm1.
- Update canonical libevent to version 2.1.8-stable-4ubuntu0.1~esm1.
- Update canonical libevent to version 2.1.11-stable-1ubuntu0.1~esm1.
- Update canonical libevent to version 2.1.12-stable-1ubuntu0.1.
- Update canonical libevent to version 2.1.12-stable-9ubuntu2.1.
- Update canonical libevent to version 2.1.12-stable-10ubuntu0.1.
- Update bellsoft libevent to version 2.1.13-r0.
- Update debian libevent to version 2.1.13-stable-1.
- Update debian libevent to version 2.1.12-stable-1.aikido.1.
- Update debian libevent to version 2.1.12-stable-8.aikido.2.
- Update debian rootio-libevent to version 2.1.12-stable-8.aikido.2.
- Update debian libevent to version 2.1.12-stable-10.aikido.1.
- Update debian rootio-libevent to version 2.1.12-stable-10.aikido.1.
- Update debian libevent to version 2.1.12-stable-8.aikido.3.
- Update debian rootio-libevent to version 2.1.12-stable-8.aikido.3.
- Update debian rootio-libevent to version 2.1.12-stable-1.aikido.1.
- Update debian libevent to version 2.1.12-stable-1.aikido.2.
- Update debian rootio-libevent to version 2.1.12-stable-1.aikido.2.
- Update debian libevent to version 2.1.12-stable-10.aikido.2.
- Update debian rootio-libevent to version 2.1.12-stable-10.aikido.2.
- Update libevent to version 2.1.12-stable-1.aikido.3.
- Update rootio-libevent to version 2.1.12-stable-1.aikido.3.
- Update debian libevent to version 2.1.12-stable-8+deb12u1.
- Update debian libevent to version 2.1.13-stable-1~deb13u1.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Ubuntu:Pro:14.04:LTS | canonical | libevent |
< 2.0.21-stable-1ubuntu1.14.04.2+esm1 Fix: upgrade to 2.0.21-stable-1ubuntu1.14.04.2+esm1
|
| Ubuntu:Pro:16.04:LTS | canonical | libevent |
< 2.0.21-stable-2ubuntu0.16.04.1+esm1 Fix: upgrade to 2.0.21-stable-2ubuntu0.16.04.1+esm1
|
| Ubuntu:Pro:18.04:LTS | canonical | libevent |
< 2.1.8-stable-4ubuntu0.1~esm1 Fix: upgrade to 2.1.8-stable-4ubuntu0.1~esm1
|
| Ubuntu:Pro:20.04:LTS | canonical | libevent |
< 2.1.11-stable-1ubuntu0.1~esm1 Fix: upgrade to 2.1.11-stable-1ubuntu0.1~esm1
|
| Ubuntu:22.04:LTS | canonical | libevent |
< 2.1.12-stable-1ubuntu0.1 Fix: upgrade to 2.1.12-stable-1ubuntu0.1
|
| Ubuntu:24.04:LTS | canonical | libevent |
< 2.1.12-stable-9ubuntu2.1 Fix: upgrade to 2.1.12-stable-9ubuntu2.1
|
| Ubuntu:26.04:LTS | canonical | libevent |
< 2.1.12-stable-10ubuntu0.1 Fix: upgrade to 2.1.12-stable-10ubuntu0.1
|
| Alpaquita:23 | bellsoft | libevent |
>= 2.1.12-r5, < 2.1.13-r0 Fix: upgrade to 2.1.13-r0
|
| Alpaquita:25 | bellsoft | libevent |
>= 2.1.12-r8, < 2.1.13-r0 Fix: upgrade to 2.1.13-r0
|
| Alpaquita:stream | bellsoft | libevent |
>= 2.1.12-r4, < 2.1.13-r0 Fix: upgrade to 2.1.13-r0
|
| BellSoft Hardened Containers:25 | bellsoft | libevent |
>= 2.1.12-r8, < 2.1.13-r0 Fix: upgrade to 2.1.13-r0
|
| BellSoft Hardened Containers:stream | bellsoft | libevent |
>= 2.1.12-r4, < 2.1.13-r0 Fix: upgrade to 2.1.13-r0
|
| – | libevent | libevent | >= 2.2.0-alpha, < 2.2.2-alpha |
| Debian:12 | debian | libevent |
< 2.1.12-stable-8+deb12u1 Fix: upgrade to 2.1.12-stable-8+deb12u1
|
| Debian:13 | debian | libevent |
< 2.1.13-stable-1~deb13u1 Fix: upgrade to 2.1.13-stable-1~deb13u1
|
| Debian:11 | debian | libevent | All versions |
| Debian:14 | debian | libevent |
< 2.1.13-stable-1 Fix: upgrade to 2.1.13-stable-1
|
| Ubuntu:14.04:LTS | canonical | libevent | All versions |
| Ubuntu:16.04:LTS | canonical | libevent | All versions |
| Ubuntu:18.04:LTS | canonical | libevent | All versions |
| Ubuntu:20.04:LTS | canonical | libevent | All versions |
| Root:Debian:11 | debian | libevent |
< 2.1.12-stable-1.aikido.1 < 2.1.12-stable-1.aikido.2 Fix: upgrade to 2.1.12-stable-1.aikido.1
|
| Root:Debian:12 | debian | libevent |
< 2.1.12-stable-8.aikido.2 < 2.1.12-stable-8.aikido.3 Fix: upgrade to 2.1.12-stable-8.aikido.2
|
| Root:Debian:12 | debian | rootio-libevent |
< 2.1.12-stable-8.aikido.2 < 2.1.12-stable-8.aikido.3 Fix: upgrade to 2.1.12-stable-8.aikido.2
|
| Root:Debian:13 | debian | libevent |
< 2.1.12-stable-10.aikido.1 < 2.1.12-stable-10.aikido.2 Fix: upgrade to 2.1.12-stable-10.aikido.1
|
| Root:Debian:13 | debian | rootio-libevent |
< 2.1.12-stable-10.aikido.1 < 2.1.12-stable-10.aikido.2 Fix: upgrade to 2.1.12-stable-10.aikido.1
|
| BellSoft Hardened Containers:23 | bellsoft | libevent |
>= 2.1.12-r5, < 2.1.13-r0 Fix: upgrade to 2.1.13-r0
|
| Root:Debian:11 | debian | rootio-libevent |
< 2.1.12-stable-1.aikido.1 < 2.1.12-stable-1.aikido.2 Fix: upgrade to 2.1.12-stable-1.aikido.1
|
| Root:Debian:11 | – | libevent |
< 2.1.12-stable-1.aikido.3 Fix: upgrade to 2.1.12-stable-1.aikido.3
|
| Root:Debian:11 | – | rootio-libevent |
< 2.1.12-stable-1.aikido.3 Fix: upgrade to 2.1.12-stable-1.aikido.3
|
Original advisory text
CVE-2026-63385 in libevent - Patched by Root
Root has patched CVE-2026-63385 in the libevent package for Root:Debian:11. Multiple fixed versions available.
References
- https://docs.bell-sw.com/security/cves/CVE-2026-63385 Vendor Advisory
- https://ubuntu.com/security/CVE-2026-63385 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-63385 Third Party Advisory
- https://ubuntu.com/security/notices/USN-8710-1 Vendor Advisory
- https://github.com/libevent/libevent/releases/tag/release-2.2.2-alpha URL
- https://github.com/libevent/libevent/security/advisories/GHSA-jcwh-pvf2-73p2 Vendor Advisory
- https://security-tracker.debian.org/tracker/CVE-2026-63385 Vendor Advisory
- https://github.com/libevent/libevent/releases/tag/release-2.1.13-stable URL
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63385... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-63385 Vendor Advisory
- https://github.com/libevent/libevent/commit/758be0c0f69c1934ef9a84ab39e9f9e5fde2... Patch
- https://github.com/libevent/libevent/commit/9170dd35e64714613e8d13b290587cfc28e2... Patch
Severity
9.4
Critical
CVSS 4.0: 9.2 (NVD)
CVSS 4.0: 9.4 (OSV)
Exploitation
EPSS <1%
Type
CWE-444Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
Timeline
Published16 Sep 2026
Updated27 Sep 2026
First seen20 Aug 2026
Sources
CVE-2026-63385 · NVD
CVE-2026-63385 · MITRE
CVE-2026-63385 · OSV
UBUNTU-CVE-2026-63385 · OSV
BELL-CVE-2026-63385 · OSV
DEBIAN-CVE-2026-63385 · OSV
GHSA-jcwh-pvf2-73p2 · GHSA
Track software like this
Free during beta