CVE-2026-63385 | Libevent up to 2.1.12 HTTP Parser http.c crlf injection

SecurityVulns

A vulnerability, which was classified as critical, has been found in Libevent up to 2.1.12. Affected is the function evhttp_decode_uri_internal/evhttp_header_is_valid_value of the file http.c of the component HTTP Parser. The manipulation leads to crlf injection.

This vulnerability is documented as CVE-2026-63385. The attack can be initiated remotely. There is not any exploit available.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More