{"apiVersion":"1.0","identifier":"CVE-2026-63495","description":"Libevent is an event notification library. From 2.2.0-alpha-dev until 2.2.2-alpha, the libevent WebSocket server in ws.c accumulates fragmented frames in evws->incomplete_frames without enforcing a total message-size limit. An unauthenticated remote client can repeatedly send fragmented WebSocket frames below WS_MAX_RECV_FRAME_SZ with FIN=0, causing the evbuffer to grow without bound until the process or host exhausts memory. This issue is fixed in version 2.2.2-alpha.","publishedAt":"2026-08-20T18:16:37","lastModifiedAt":"2026-08-20T20:17:45","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-63495","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","epssProbability":0.00426,"riskScore":0.78,"affectedProduct":"libevent","affectedVersions":">=2.2.0-alpha-dev, <2.2.2-alpha","vulnerabilityType":"Library","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-63495","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-63495","en":"https://www.redsauce.net/en/cves/CVE-2026-63495","fr":"https://www.redsauce.net/fr/cves/CVE-2026-63495","pt":"https://www.redsauce.net/pt/cves/CVE-2026-63495","de":"https://www.redsauce.net/de/cves/CVE-2026-63495","sk":"https://www.redsauce.net/sk/cves/CVE-2026-63495","el":"https://www.redsauce.net/el/cves/CVE-2026-63495"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-63495"}}