Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2026-63385: libevent library allows remote code execution

CVE-2026-63385 · published 13 days ago
Summary

The libevent library used in several Linux distributions can be tricked into running malicious code. This could let an attacker take control of the affected system. Apply the latest updates for libevent from your Linux vendor as soon as possible.

What to do
  • Update canonical libevent to version 2.0.21-stable-1ubuntu1.14.04.2+esm1.
  • Update canonical libevent to version 2.0.21-stable-2ubuntu0.16.04.1+esm1.
  • Update canonical libevent to version 2.1.8-stable-4ubuntu0.1~esm1.
  • Update canonical libevent to version 2.1.11-stable-1ubuntu0.1~esm1.
  • Update canonical libevent to version 2.1.12-stable-1ubuntu0.1.
  • Update canonical libevent to version 2.1.12-stable-9ubuntu2.1.
  • Update canonical libevent to version 2.1.12-stable-10ubuntu0.1.
  • Update bellsoft libevent to version 2.1.13-r0.
  • Update debian libevent to version 2.1.13-stable-1.
  • Update debian libevent to version 2.1.12-stable-1.aikido.1.
  • Update debian libevent to version 2.1.12-stable-8.aikido.2.
  • Update debian rootio-libevent to version 2.1.12-stable-8.aikido.2.
  • Update debian libevent to version 2.1.12-stable-10.aikido.1.
  • Update debian rootio-libevent to version 2.1.12-stable-10.aikido.1.
  • Update debian libevent to version 2.1.12-stable-8.aikido.3.
  • Update debian rootio-libevent to version 2.1.12-stable-8.aikido.3.
  • Update debian rootio-libevent to version 2.1.12-stable-1.aikido.1.
  • Update debian libevent to version 2.1.12-stable-1.aikido.2.
  • Update debian rootio-libevent to version 2.1.12-stable-1.aikido.2.
  • Update debian libevent to version 2.1.12-stable-10.aikido.2.
  • Update debian rootio-libevent to version 2.1.12-stable-10.aikido.2.
  • Update libevent to version 2.1.12-stable-1.aikido.3.
  • Update rootio-libevent to version 2.1.12-stable-1.aikido.3.
  • Update debian libevent to version 2.1.12-stable-8+deb12u1.
  • Update debian libevent to version 2.1.13-stable-1~deb13u1.
Affected software
Ecosystem VendorProductAffected versions
Ubuntu:Pro:14.04:LTS canonical libevent < 2.0.21-stable-1ubuntu1.14.04.2+esm1
Fix: upgrade to 2.0.21-stable-1ubuntu1.14.04.2+esm1
Ubuntu:Pro:16.04:LTS canonical libevent < 2.0.21-stable-2ubuntu0.16.04.1+esm1
Fix: upgrade to 2.0.21-stable-2ubuntu0.16.04.1+esm1
Ubuntu:Pro:18.04:LTS canonical libevent < 2.1.8-stable-4ubuntu0.1~esm1
Fix: upgrade to 2.1.8-stable-4ubuntu0.1~esm1
Ubuntu:Pro:20.04:LTS canonical libevent < 2.1.11-stable-1ubuntu0.1~esm1
Fix: upgrade to 2.1.11-stable-1ubuntu0.1~esm1
Ubuntu:22.04:LTS canonical libevent < 2.1.12-stable-1ubuntu0.1
Fix: upgrade to 2.1.12-stable-1ubuntu0.1
Ubuntu:24.04:LTS canonical libevent < 2.1.12-stable-9ubuntu2.1
Fix: upgrade to 2.1.12-stable-9ubuntu2.1
Ubuntu:26.04:LTS canonical libevent < 2.1.12-stable-10ubuntu0.1
Fix: upgrade to 2.1.12-stable-10ubuntu0.1
Alpaquita:23 bellsoft libevent >= 2.1.12-r5, < 2.1.13-r0
Fix: upgrade to 2.1.13-r0
Alpaquita:25 bellsoft libevent >= 2.1.12-r8, < 2.1.13-r0
Fix: upgrade to 2.1.13-r0
Alpaquita:stream bellsoft libevent >= 2.1.12-r4, < 2.1.13-r0
Fix: upgrade to 2.1.13-r0
BellSoft Hardened Containers:25 bellsoft libevent >= 2.1.12-r8, < 2.1.13-r0
Fix: upgrade to 2.1.13-r0
BellSoft Hardened Containers:stream bellsoft libevent >= 2.1.12-r4, < 2.1.13-r0
Fix: upgrade to 2.1.13-r0
– libevent libevent >= 2.2.0-alpha, < 2.2.2-alpha
Debian:12 debian libevent < 2.1.12-stable-8+deb12u1
Fix: upgrade to 2.1.12-stable-8+deb12u1
Debian:13 debian libevent < 2.1.13-stable-1~deb13u1
Fix: upgrade to 2.1.13-stable-1~deb13u1
Debian:11 debian libevent All versions
Debian:14 debian libevent < 2.1.13-stable-1
Fix: upgrade to 2.1.13-stable-1
Ubuntu:14.04:LTS canonical libevent All versions
Ubuntu:16.04:LTS canonical libevent All versions
Ubuntu:18.04:LTS canonical libevent All versions
Ubuntu:20.04:LTS canonical libevent All versions
Root:Debian:11 debian libevent < 2.1.12-stable-1.aikido.1
< 2.1.12-stable-1.aikido.2
Fix: upgrade to 2.1.12-stable-1.aikido.1
Root:Debian:12 debian libevent < 2.1.12-stable-8.aikido.2
< 2.1.12-stable-8.aikido.3
Fix: upgrade to 2.1.12-stable-8.aikido.2
Root:Debian:12 debian rootio-libevent < 2.1.12-stable-8.aikido.2
< 2.1.12-stable-8.aikido.3
Fix: upgrade to 2.1.12-stable-8.aikido.2
Root:Debian:13 debian libevent < 2.1.12-stable-10.aikido.1
< 2.1.12-stable-10.aikido.2
Fix: upgrade to 2.1.12-stable-10.aikido.1
Root:Debian:13 debian rootio-libevent < 2.1.12-stable-10.aikido.1
< 2.1.12-stable-10.aikido.2
Fix: upgrade to 2.1.12-stable-10.aikido.1
BellSoft Hardened Containers:23 bellsoft libevent >= 2.1.12-r5, < 2.1.13-r0
Fix: upgrade to 2.1.13-r0
Root:Debian:11 debian rootio-libevent < 2.1.12-stable-1.aikido.1
< 2.1.12-stable-1.aikido.2
Fix: upgrade to 2.1.12-stable-1.aikido.1
Root:Debian:11 – libevent < 2.1.12-stable-1.aikido.3
Fix: upgrade to 2.1.12-stable-1.aikido.3
Root:Debian:11 – rootio-libevent < 2.1.12-stable-1.aikido.3
Fix: upgrade to 2.1.12-stable-1.aikido.3
Original advisory text
CVE-2026-63385 in libevent - Patched by Root
Root has patched CVE-2026-63385 in the libevent package for Root:Debian:11. Multiple fixed versions available.
Severity
9.4 Critical
CVSS 4.0: 9.2 (NVD)
CVSS 4.0: 9.4 (OSV)
Exploitation
EPSS <1%
Type
CWE-444Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
Timeline
Published16 Sep 2026
Updated27 Sep 2026
First seen20 Aug 2026
Track software like this
Free during beta