These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-63495 is a high-severity vulnerability in the Libevent library, which can lead to a denial-of-service (DoS) attack due to an unbounded memory growth issue in the WebSocket server. This issue affects Libevent versions from 2.2.0-alpha-dev to 2.2.2-alpha. An unauthenticated remote client can exploit this vulnerability by sending fragmented WebSocket frames, causing the evbuffer to grow without boun [truncated]
The libevent library, used for event notification, has a heap out-of-bounds write vulnerability in bufferevent_sock.c. This issue arises when bufferevent_socket_set_conn_address_ copies a kernel-supplied AF_UNIX peer address into bufferevent_private.conn_address, potentially leading to memory corruption. The vulnerability impacts confidentiality, integrity, and availability. Developers and administrators [truncated]
CVE-2026-63387 is a high-severity vulnerability in the Libevent event notification library, caused by an off-by-one stack buffer overflow in evdns.c when formatting a name-bearing DNS record. A crafted DNS server response can trigger the one-byte out-of-bounds write and crash or corrupt the process. This issue is fixed in Libevent versions 2.1.13 and 2.2.2-alpha. Defenders responsible for systems using Li [truncated]
Libevent is an event notification library with two HTTP parsing weaknesses in http.c. CVE-2026-63385 describes vulnerabilities in percent-encoded %00 bytes and obsolete line folding in header values. Patches are available in Libevent versions 2.1.13 and 2.2.2-alpha. The CVE record was published on 2026-08-20T18:16:36.543Z and has not been modified since then. Affected product deployments should be reviewe [truncated]
CVE-2026-63384 is a denial-of-service vulnerability in the Libevent event notification library. An incorrect integer conversion in event_tagging.c can lead to a large allocation request and service disruption. The issue is fixed in versions 2.1.13 and 2.2.2-alpha. Affected product deployments should be assessed for exposure, and defenders should prioritize patching or upgrading to fixed versions to preven [truncated]
CVE-2026-63383 is a vulnerability in the Libevent event notification library, which can cause an out-of-bounds read when decoding tagged RPC data, potentially crashing a process. This issue arises from a problem in event_tagging.c where decode_tag_internal requests at most five bytes from evbuffer_pullup but iterates using the full logical buffer length. A fragmented evbuffer containing a six-byte malform [truncated]
CVE-2026-63382 is a critical vulnerability in the Libevent event notification library. An unauthenticated remote attacker can exploit this issue to desynchronize request boundaries and smuggle a second request, potentially bypassing access controls or poisoning caches when Libevent is deployed behind a proxy that frames the same request differently. The issue is fixed in Libevent versions 2.1.13 and 2.2.2-alpha.
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-20T18:16:35.530Z and has not been modified since then. The NVD entry is currently MEDIUM. The libevent library has a use-after-free vulnerability in buffer.c when evbuffer_add_buffer_reference processes an output buffer with out_total_len set to zero. This can lead to memory corruption or process cr [truncated]
A local attacker can crash a process using libevent by inducing an allocation or locking failure. The issue is fixed in version 2.2.2-alpha. This vulnerability affects systems using libevent, and defenders should assess exposure and prioritize applying the patch. The vulnerability involves a local attacker inducing an allocation or locking failure, which can lead to a process crash. The fix is included in [truncated]
CVE-2026-63379 is a vulnerability in the Libevent event notification library. An unauthenticated remote attacker can exploit this issue to enable header smuggling, authorization bypass, proxy-header spoofing, or cache poisoning by placing security-sensitive fields in HTTP trailers. The issue is fixed in Libevent versions 2.1.13 and 2.2.2-alpha. Affected deployments require verification and patch applicati [truncated]