Skip to main content
Version: v1.3.x

CVE-2026-63387

CVE Details

Visit the official vulnerability details page for CVE-2026-63387 to learn more.

Initial Publication

08/20/2026

Last Update

08/25/2026

Third Party Dependency

libevent

NIST CVE Summary

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an off-by-one stack buffer overflow in evdns.c when dnsname_to_labels formats a name-bearing DNS record at the end of the 64 KB stack buffer allocated by evdns_server_request_format_response. The final-label check permits j plus label_len plus one to equal buf_len, after which the terminating null byte is written to buf[buf_len]. A crafted DNS server response containing PTR, CNAME, MX, NS, or SOA data can trigger the one-byte out-of-bounds write and crash or corrupt the process. This issue is fixed in versions 2.1.13 and 2.2.2-alpha.

CVE Severity

7

Our Official Summary

Investigation is ongoing to determine how this vulnerability affects our products.

Status

Received

Affected Products & Versions

VersionPaletteAIPaletteAI VerteX
1.3.0⚠️ Impacted⚠️ Impacted
1.2.2⚠️ Impacted⚠️ Impacted

Revision History

No revisions available.