Skip to main content
Version: v1.3.x

CVE-2026-63385

CVE Details

Visit the official vulnerability details page for CVE-2026-63385 to learn more.

Initial Publication

08/20/2026

Last Update

09/09/2026

Third Party Dependency

libevent

NIST CVE Summary

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has two HTTP parsing weaknesses in http.c. evhttp_decode_uri_internal decodes percent-encoded %00 bytes into literal NUL characters, which can cause downstream C string operations to truncate a path and bypass validation performed on a different representation. evhttp_header_is_valid_value also accepts obsolete line folding in header values containing carriage return or line feed characters, allowing a proxy and libevent to interpret headers differently and enabling header injection or access control bypass. The CRLF header acceptance is fixed in versions 2.1.13 and 2.2.2-alpha, but the reviewed patches do not clearly remediate the URI NUL-truncation condition.

CVE Severity

9.2

Our Official Summary

Investigation is ongoing to determine how this vulnerability affects our products.

Status

Awaiting Analysis

Affected Products & Versions

VersionPaletteAIPaletteAI VerteX
1.3.2⚠️ Impacted⚠️ Impacted
1.2.2⚠️ Impacted⚠️ Impacted

Revision History

No revisions available.