CVE-2026-63380 | Libevent up to 2.2.1 WebSocket Session Management ws.c evws_new_session null pointer dereference

SecurityVulns

A vulnerability identified as problematic has been detected in Libevent up to 2.2.1. This issue affects the function evws_new_session of the file ws.c of the component WebSocket Session Management. The manipulation leads to null pointer dereference.

This vulnerability is referenced as CVE-2026-63380. The attack can only be performed from a local environment. No exploit is available.

You should upgrade the affected component.VulDB Recent EntriesRead More