Maintainers of libevent and libexpat (Expat) released security updates to fix multiple high-severity vulnerabilities affecting widely used networking and XML parsing components. libevent 2.1.13-stable and 2.2.2-alpha remediate memory-safety bugs across evbuffer, bufferevent, evtag, evrpc, evdns, and evhttp, including out-of-bounds reads and writes, integer overflow, and a dangling pointer, alongside HTTP parsing weaknesses that could enable request smuggling, header smuggling, parser mismatch, and access-control bypass. One libevent fix tightened chunked-transfer parsing to require strict CRLF handling in line with RFC 9112, while later CVE records identified issues such as signed/unsigned length conversion in evtag_unmarshal_header() (CVE-2026-63384) and HTTP header and URI parsing bugs (CVE-2026-63385) in versions prior to the patched releases.
libexpat 2.8.2 was published to fix 14 vulnerabilities spanning integer overflows, out-of-bounds writes, missing control-flow integrity checks, and unsafe parser API behavior in functions including XML_ParseBuffer, storeAtts, addBinding, getAttributeId, and doProlog, as well as several flaws in the xmlwf utility. A subsequent high-severity disclosure, CVE-2026-76641, showed that Expat versions through 2.8.3 still contained an out-of-bounds read in external entity parsing caused by a struct size mismatch introduced by an earlier fix, creating risks of memory corruption, wild-pointer dereference, and denial of service. Together, the disclosures highlight continued patching activity for foundational open-source libraries embedded in network-facing and XML-processing software.

See affected versions and whether adversaries are exploiting it.
10 events from the most recent confirmed update back to the earliest known activity.
On 2026-08-20, a CVE record was received for CVE-2026-76641, an out-of-bounds read in libexpat affecting versions through 2.8.3 during XML external entity parsing. The flaw was described as introduced by the fix for CVE-2026-66046 and can lead to memory corruption or a segmentation fault.
On 2026-08-20, CVE-2026-63388 was published for a libevent vulnerability with no known exploits reported. A Tenable Nessus plugin identified affected libevent packages on Ubuntu 14.04 through 26.04 LTS and Debian 11.0, 12.0, and 13.0 systems as unpatched.
On 2026-08-20, CVE-2026-63387 was published for a libevent vulnerability with no known exploits reported. A Tenable Nessus plugin identified affected libevent packages on Ubuntu 14.04 through 26.04 LTS and Debian 11.0, 12.0, and 13.0 systems as unpatched.
On 2026-08-20, CVE-2026-63383 was published for a network-reachable libevent vulnerability with primarily availability impact and no known exploits reported. A Tenable Nessus plugin identified Debian Linux 11.0, 12.0, and 13.0 systems with the libevent package as affected and unpatched.
On 2026-08-20, a CVE record was newly received for CVE-2026-63384, an incorrect integer conversion issue in libevent's event_tagging.c that can lead to denial of service. The record says the flaw affects versions before 2.1.13 and 2.2.0-alpha through before 2.2.2-alpha, and was fixed in 2.1.13 and 2.2.2-alpha.
On 2026-08-20, a CVE record was newly received for CVE-2026-63385 covering two libevent HTTP parsing weaknesses involving percent-encoded NUL handling and obsolete folded headers. The record states affected versions are fixed in libevent 2.1.13 and 2.2.2-alpha, while noting the URI NUL-truncation remediation was not clearly established in reviewed patches.
On 2026-06-29, libevent committed fixes in both maintained branches to require strict CRLF termination when parsing HTTP chunk sizes, aligning behavior with RFC 9112. The change was tracked as part of GHSA-q39v-w2g7-gr8j and addressed request smuggling risk.
Sebastian Pipping announced libexpat 2.8.2 on 2026-06-25 as a security release fixing a large set of Expat vulnerabilities, including integer overflows, an out-of-bounds write, and missing control flow integrity checks. The release also included follow-on fixes closing gaps in remediation for CVE-2026-50219.
On 2026-06-25, NLnet Labs disclosed four high-severity vulnerabilities in NSD and released NSD version 4.14.3 to fix them. The advisory also provided individual patches for each CVE and a combined patch tested against NSD 4.14.2.
Libevent released version 2.1.13-stable on 2026-07-01 with multiple security fixes across evbuffer, bufferevent, evtag, evrpc, evdns, and evhttp. Maintainers advised users of affected modules and distributors to upgrade, and the release notice also mentioned parallel availability of 2.2.2-alpha.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
12 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcecvefeed.io
Open sourceseclists.org
Open sourceseclists.org
Open sourceseclists.org
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.