USN-8710-1: libevent vulnerabilities
Alexis Challande discovered that libevent incorrectly handled certain empty output buffers. An attacker could possibly use this issue to trigger a use-after-free, resulting in a denial of service or arbitrary code execution. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-63381) Rajat Raghav discovered that libevent incorrectly handled certain HTTP requests. An attacker could possibly use this issue to desynchronize HTTP request boundaries, resulting in HTTP request smuggling. (CVE-2026-63382) Qiu Sihao discovered that libevent incorrectly handled certain malformed tagged RPC data. An attacker could possibly use this issue to trigger an out-of-bounds read, resulting in a denial of service. (CVE-2026-63383) Qiu Sihao discovered that libevent incorrectly handled certain large payload lengths in tagged RPC data. An attacker could possibly use this issue to consume excessive system resources, resulting in a denial of service. (CVE-2026-63384) Asaf Meizner discovered that libevent incorrectly handled certain HTTP URIs and header values. An attacker could possibly use this issue to cause HTTP messages to be interpreted inconsistently, resulting in security restrictions being bypassed. (CVE-2026-63385)
CSIRTS triage
- What
- libevent has multiple vulnerabilities including use-after-free in empty output buffer handling, HTTP request smuggling, and out-of-bounds reads in RPC data parsing.
- Who is affected
- Systems running libevent on Ubuntu 18.04 LTS, 20.04 LTS, 22.04 LTS, 24.04 LTS, and 26.04 LTS.
- Urgency
- High; use-after-free can cause denial of service or arbitrary code execution, and HTTP request smuggling allows request desynchronization.
- Action
- Apply Ubuntu security updates USN-8710-1 to patch CVE-2026-63381, CVE-2026-63382, CVE-2026-63383, CVE-2026-63384, and CVE-2026-63385.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch libevent
Get an email when a new libevent advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://ubuntu.com/security/notices/USN-8710-1
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-633810.12% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-633820.59% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 46% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-633830.38% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-633840.38% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-633850.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 34% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-63381 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-63382 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-63383 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-63384 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-63385 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownDSA-6493-1 libevent - security updatedebian
- unknownCVE-2026-63385: Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has two H…nvd
- unknownCVE-2026-63384: Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an in…nvd
- unknownCVE-2026-63383: Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent can read …nvd
- unknownCVE-2026-63382: Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, the libevent evhtt…nvd
- unknownCVE-2026-63381: Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a use…nvd
- unknownCVE-2026-63385: Libevent: HTTP header handling bugs create risk of access control bypass.msrc
- unknownCVE-2026-63383: Libevent: decode_tag_internal() can lead to out-of-bounds readmsrc
- unknownCVE-2026-63384: Libevent: `evtag_unmarshal_header()` decodes a wire `uint32` length into a signed `int` return…msrc
- unknownCVE-2026-63381: Libevent: Dangling Pointer in `evbuffer_add_buffer_reference`msrc
More from Ubuntu Security Notices
- unknownUSN-8563-5: nginx vulnerability2026-09-14
- unknownUSN-8751-1: Urwid vulnerabilities2026-09-14
- unknownUSN-8750-1: FFmpeg vulnerabilities2026-09-14
- unknownUSN-8749-1: CivetWeb vulnerabilities2026-09-14
- unknownUSN-8571-2: Apache HTTP Server regression2026-09-10