CVE-2026-63382 | Libevent up to 2.1.12 Evhttp Parser http.c evhttp_find_header crlf injection

SecurityVulns

A vulnerability has been found in Libevent up to 2.1.12 and classified as critical. This impacts the function evhttp_find_header of the file http.c of the component Evhttp Parser. The manipulation leads to crlf injection.

This vulnerability is traded as CVE-2026-63382. It is possible to initiate the attack remotely. There is no exploit available.

The affected component should be upgraded.VulDB Recent EntriesRead More