Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-63495

Опубликовано: 20 авг. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Libevent is an event notification library. From 2.2.0-alpha-dev until 2.2.2-alpha, the libevent WebSocket server in ws.c accumulates fragmented frames in evws->incomplete_frames without enforcing a total message-size limit. An unauthenticated remote client can repeatedly send fragmented WebSocket frames below WS_MAX_RECV_FRAME_SZ with FIN=0, causing the evbuffer to grow without bound until the process or host exhausts memory. This issue is fixed in version 2.2.2-alpha.

A flaw was found in Libevent. An unauthenticated remote client can exploit this vulnerability by repeatedly sending fragmented WebSocket frames to the Libevent WebSocket server. Due to a lack of a total message-size limit, these fragmented frames accumulate in memory without bound, leading to memory exhaustion and a denial of service (DoS) for the process or host.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10libeventAffected
Red Hat Enterprise Linux 6libeventAffected
Red Hat Enterprise Linux 6libevent2Affected
Red Hat Enterprise Linux 7libeventAffected
Red Hat Enterprise Linux 8libeventAffected
Red Hat Enterprise Linux 9libeventAffected
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-8Affected
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-9Affected
Red Hat Hardened Imageslibevent-main-2.1.12-19.hum1FixedRHSA-2026:4117617.07.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2520659libevent: Libevent: Remote denial of service via unbounded memory accumulation in WebSocket server

EPSS

Процентиль: 36%
0.00426
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
14 дней назад

Libevent is an event notification library. From 2.2.0-alpha-dev until 2.2.2-alpha, the libevent WebSocket server in ws.c accumulates fragmented frames in evws->incomplete_frames without enforcing a total message-size limit. An unauthenticated remote client can repeatedly send fragmented WebSocket frames below WS_MAX_RECV_FRAME_SZ with FIN=0, causing the evbuffer to grow without bound until the process or host exhausts memory. This issue is fixed in version 2.2.2-alpha.

CVSS3: 7.5
nvd
14 дней назад

Libevent is an event notification library. From 2.2.0-alpha-dev until 2.2.2-alpha, the libevent WebSocket server in ws.c accumulates fragmented frames in evws->incomplete_frames without enforcing a total message-size limit. An unauthenticated remote client can repeatedly send fragmented WebSocket frames below WS_MAX_RECV_FRAME_SZ with FIN=0, causing the evbuffer to grow without bound until the process or host exhausts memory. This issue is fixed in version 2.2.2-alpha.

CVSS3: 7.5
debian
14 дней назад

Libevent is an event notification library. From 2.2.0-alpha-dev until ...

CVSS3: 7.5
fstec
2 месяца назад

Уязвимость файла ws.c WebSocket-сервера библиотеки асинхронного уведомления о событиях Libevent, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 36%
0.00426
Низкий

7.5 High

CVSS3